CyclopsBlink
Cyclops Blink
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink… Fuente: MISP
Actividad en Jábega · 12 semanas
1 noticias · vista por primera vez el 14 sept 2026 · la última, el 14 sept 2026
Noticias
- 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 14 sept 2026
Aparece junto a
Técnicas MITRE ATT&CK
Ejecución
Persistencia
Descubrimiento
T1016System Network Configuration Discovery 4 reglas SigmaT1057Process Discovery 3 reglas SigmaT1082System Information Discovery 18 reglas SigmaT1083File and Directory Discovery 17 reglas Sigma
Recopilación
Mando y control
T1071.001Web Protocols 39 reglas SigmaT1090.003Multi-hop Proxy 3 reglas SigmaT1105Ingress Tool Transfer 40 reglas SigmaT1132.002Non-Standard EncodingT1571Non-Standard Port 5 reglas SigmaT1572Protocol Tunneling 23 reglas SigmaT1573.002Asymmetric Cryptography
Exfiltración
Stealth
T1036.005Match Legitimate Resource Name or Location 20 reglas SigmaT1070.006Timestomp 4 reglas SigmaT1140Deobfuscate/Decode Files or Information 17 reglas Sigma
Defense impairment
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗