Russia-linked Sandworm reportedly has retooled with 'Cyclops Blink'
Full article623 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The "large-scale modular malware framework" has largely replaced the "VPNFilter" tools that Sandworm used before they were disrupted in 2018.
A long-running hacking group associated with Russian intelligence has developed a new set of tools to replace malware that was disrupted in 2018, according to an alert Wednesday from the U.S. and U.K. cybersecurity and law enforcement agencies.
The advanced persistent threat group, known primarily as Sandworm, is now using a “large-scale modular malware framework” that the agencies call Cyclops Blink. Western governments have blamed Sandworm for major incidents such as the disruption of Ukraine’s electricity grid in 2015, the the NotPetya attacks in 2017 and breaches of the Winter Olympics in 2018.
Cyclops Blink has largely replaced the VPNFilter malware in Sandworm’s activities since at least June 2019, said the joint alert from the U.K.’s National Cyber Security Centre (NCSC), and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI in the U.S. The NCSC also issued a separate analysis paper on Cyclops Blink.
The announcement arrives as one of Sandworm’s primary targets, Ukraine, faces a Russian invasion force within its borders. With that threat as a backdrop, U.S. and U.K. agencies hurried last week to attribute DDoS incidents against banking and government websites to Russia’s GRU. More DDoS attacks were reported Wednesday. John Hultquist, vice president of Threat Intelligence at Mandiant and an experienced tracker of Sandworm’s activities, tweeted that the timing of Wednesday’s alert “couldn’t have been much better.”
VPNFilter, used in the 2015 Ukraine attacks and 2018 Olympics incident, was exposed by cybersecurity researchers at Cisco Talos in 2018 and disrupted by the U.S. Department of Justice. Sandworm is typically linked to the GRU, Russia’s main intelligence directorate.
The new tools operate in a familiar fashion to VPNFilter by propagating through a custom botnet, the alert said. The chief targets are Firebox devices by WatchGuard, a manufacturer of firewall hardware for home offices and small networks. The Seattle-based company has been working closely with U.S. and U.K. agencies to block the malware on its products, the alert said.
“The actor has so far primarily deployed Cyclops Blink to WatchGuard devices, but it is likely that Sandworm would be capable of compiling the malware for other architectures and firmware,” the alert said.
The malware enters devices through a fake firmware update, according to the NCSC’s malware analysis, and can persist on a machine even after it has an authentic firmware update.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sandworm-new-malware-cyclops-blink/