CyclopsBlink
Cyclops Blink
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink… Source: MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 14 Sep 2026 · last seen on 14 Sep 2026
News
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 14 Sep 2026
Appears alongside
MITRE ATT&CK techniques
Execution
Persistence
Discovery
T1016System Network Configuration Discovery 4 Sigma rulesT1057Process Discovery 3 Sigma rulesT1082System Information Discovery 18 Sigma rulesT1083File and Directory Discovery 17 Sigma rules
Collection
Command and Control
T1071.001Web Protocols 39 Sigma rulesT1090.003Multi-hop Proxy 3 Sigma rulesT1105Ingress Tool Transfer 40 Sigma rulesT1132.002Non-Standard EncodingT1571Non-Standard Port 5 Sigma rulesT1572Protocol Tunneling 23 Sigma rulesT1573.002Asymmetric Cryptography
Exfiltration
Stealth
T1036.005Match Legitimate Resource Name or Location 20 Sigma rulesT1070.006Timestomp 4 Sigma rulesT1140Deobfuscate/Decode Files or Information 17 Sigma rules
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗