CYCLOPS BLINK is a modular botnet malware built and operated by Sandworm Team, the Russian GRU's Unit 74455, that quietly compromised thousands of WatchGuard Firebox/XTM firewalls and ASUS home/small-office routers around the world starting around June 2019 — roughly fourteen months after Sandworm's previous botnet, VPNFilter, was publicly exposed and disrupted by the FBI in May 2018 (CISA AA22-054A, Feb 23 2022). It sat undiscovered for approximately two and a half years before a joint CISA/FBI/NSA/NCSC-UK advisory revealed its existence on February 23, 2022 — one day before Russia's full-scale invasion of Ukraine — and a U.S. Department of Justice court-authorized operation remotely disabled the botnet's remaining command-and-control nodes the following month.
Why it matters: CYCLOPS BLINK is the clearest documented example of a nation-state building durable, long-term botnet infrastructure specifically on network-edge devices — firewalls and consumer/SOHO routers — precisely because those devices sit outside the reach of the endpoint monitoring, EDR telemetry, and internal-network logging that would normally catch a multi-year intrusion. Unlike a traditional espionage operation aimed at stealing a specific target's data, CYCLOPS BLINK's design and behavior (see Section 03) reflect infrastructure-building for future, unspecified use — a proxy and staging layer Sandworm could draw on when needed, not a campaign against any single victim.
Its proximity to the Ukraine invasion generated significant contemporaneous speculation that the botnet was being prepared for use in or alongside the war — CISA's advisory itself was published with explicit "shields up" framing amid heightened concern about Russian cyber activity tied to the invasion. It is important to be precise about what is and is not established here: public sources reviewed for this card document that the botnet existed, was operated by Sandworm, and was disabled before any confirmed offensive use — they do not establish a proven, specific intent to use it against Ukraine or NATO targets. That distinction between documented fact and contemporaneous framing is preserved throughout this card (see Section 07 and Section 09).
This is also the second time the exact same disruption playbook — a DOJ-authorized, FBI-executed remote remediation operation — was run against Sandworm-operated botnet infrastructure specifically, after VPNFilter in 2018. That repetition is itself analytically significant: it establishes court-authorized remote botnet remediation as a standing, repeatable U.S. government tool against this class of nation-state infrastructure, not a one-off legal improvisation (see Section 07C and Section 09).
Direct historical precedent — VPNFilter (2018). In May 2018, Cisco Talos and the FBI exposed and disrupted VPNFilter, a Sandworm-operated botnet that had compromised over 500,000 SOHO routers and network-attached storage devices across 54 countries (Cisco Talos, May 2018; DOJ, May 2018). The FBI seized a domain used in VPNFilter's command-and-control chain under a court-authorized warrant. CISA's later advisory on Cyclops Blink states plainly that the new malware appeared "fourteen months after VPNFilter was disrupted" and functions as its replacement framework — the same actor, the same target category (network-edge devices), and, as this incident shows, ultimately the same disruption mechanism.
Technology landscape. By 2019, WatchGuard Firebox/XTM appliances and ASUS routers were widely deployed in small-business and home environments precisely because they are largely "install and forget" devices — appliances that receive periodic firmware updates but are not treated by their owners, or by the broader security industry, as endpoints requiring active monitoring the way a laptop or server would be. This operational reality is what makes the device class attractive to an actor building long-term infrastructure: low monitoring, wide deployment, and firmware-level access once compromised.
Geopolitical climate. The campaign's active window (2019–2022) spans a period of steadily escalating tension between Russia and the West, culminating in the February 24, 2022 invasion of Ukraine. Sandworm has a well-documented history of destructive and disruptive operations tied to Russia's conflict with Ukraine specifically (see actor card, Section 02) — the 2015 and 2016 Ukrainian power grid attacks, NotPetya in 2017. CYCLOPS BLINK's discovery one day before the invasion, in an advisory explicitly framed around "shields up" concern, sits inside that pattern even though — as stated in Section 01 — no source reviewed confirms the botnet was built or earmarked specifically for use against Ukraine.
Pre-incident indicators. No public source reviewed for this card documents any pre-2022 detection, alert, or customer report that identified Cyclops Blink activity before the joint advisory — this was, by all available evidence, a genuinely blind multi-year run for defenders (see Section 05).
install_upgrade component) with modified versions, meaning it survives reboots and ordinary restarts — the two things that would normally clear a less sophisticated implant (NCSC Malware Analysis Report, Feb 23 2022).| Type | Value / Description | Source | Date |
|---|---|---|---|
| CVE | CVE-2022-23176 (WatchGuard Firebox/XTM privilege escalation) | CISA / NVD | 2022-02-23 |
| MALWARE ID | MITRE ATT&CK Software S0687 (Cyclops Blink) | MITRE ATT&CK | 2022 |
| BEHAVIORAL | TLS-wrapped C2 traffic on device management plane, tiered/clustered C2 IP lists, AES-256-CBC-encrypted payload, Tor-relayed operator access | NCSC Malware Analysis Report | 2022-02-23 |
| BEHAVIORAL | Unauthorized firmware "update" event on WatchGuard Firebox/XTM device outside a logged, administrator-initiated upgrade action | WatchGuard / CISA remediation guidance | 2022 |
| NOTE | No specific C2 IP addresses, domains, or file hashes for Cyclops Blink samples were located in the public-source subset reviewed for this card (CISA/NCSC published detailed detection signatures and YARA/Snort rules in companion technical documents not fully mirrored in the sources retrieved here). This is stated as a research-pass gap, not a claim that no such IOCs exist publicly — an analyst needing operational IOCs should pull directly from the NCSC Malware Analysis Report PDF and CISA's companion indicator files. | ||
Attribution here rests on formal, joint technical assessment by four government cybersecurity agencies across two allied nations (CISA, FBI, and NSA in the U.S.; NCSC in the UK), publishing consistent findings under a shared advisory. This is a stronger evidentiary basis than a single-vendor private assessment, and it is consistent with — not standing apart from — the broader body of independent vendor tracking (CrowdStrike's VOODOO BEAR, ESET's TeleBots, Dragos's ELECTRUM, Microsoft's Seashell Blizzard/IRIDIUM, all converging on the same underlying actor cluster; see actor card Section 01 for the full alias/tracking-designation picture). No source reviewed for this card raises a serious competing attribution hypothesis. Full identity, sponsorship, and confidence-rationale detail for the actor itself lives in the companion Sandworm Team actor card rather than being duplicated here, per this card's relationship to actor cards.
CYCLOPS BLINK is the second confirmed case of the U.S. Department of Justice using a court-authorized, remote, non-consensual remediation operation to disable a Sandworm-operated botnet — the first being VPNFilter in 2018. Two data points is a thin base for declaring a "doctrine," but it is enough to establish that this specific legal and operational mechanism is now a standing, repeatable tool in the U.S. government's toolkit against nation-state edge-device botnet infrastructure, rather than a one-time legal improvisation. Any future incident card documenting a similar takedown should treat this pairing (VPNFilter → Cyclops Blink) as the baseline precedent, not a novel development.
It is also one of the clearest documented cases of a nation-state building large-scale botnet infrastructure as a standing capability rather than as a tool aimed at a specific target or objective — the "dormant pre-positioning" model described in Section 03. That distinction matters for how defenders and policymakers should think about network-edge device compromise generally: the absence of any confirmed offensive use of the botnet before it was disrupted does not mean the compromise was low-stakes while it lasted. It means the capability existed, fully formed and ready, for roughly two and a half years before anyone outside Sandworm knew about it — a genuinely different risk profile than an intrusion aimed at immediate data theft, and one that argues for treating "silent, purposeless-seeming" edge-device compromise as seriously as an active, damaging one.
Finally, the incident is a clean case study in how vulnerability disclosure interacts with active law-enforcement operations (see the companion vuln card's Section 04 and Section 07 for the fuller analysis) — WatchGuard patched the underlying CVE quietly in December 2021 and held back public framing of its severity for roughly two months at DOJ's direction, ahead of the March 2022 takedown. That is a genuinely different disclosure model than the standard researcher-vendor coordinated disclosure this field is usually taught around, and it remains a live, unresolved tension worth studying on its own terms rather than folding into ordinary CVD norms.