Cyclops-Blink-Malware-Analysis-Report.pdf
ID: ac63fee4-8936-4644-a244-d47eca0dc644
STIX ID: report--ac63fee4-8936-4644-a244-d47eca0dc644
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2022-02-23
Last Modified Date: 2022-02-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
Cyclops Blink is a sophisticated, modular Linux ELF malware targeting SOHO network devices (notably WatchGuard Firebox) that achieves persistent infection by modifying the firmware update process (including recalculating firmware HMAC), implements modular reconnaissance, file transfer and update components, and communicates with encrypted C2 channels (AES-256-CBC under TLS) using hard-coded RSA keys; the report includes sample metadata, IOCs (paths, hashes, C2 IPs), MITRE ATT&CK mappings and YARA detection rules.
