In a court-authorized March operation, the FBI cut off the servers of the Cyclops Blink botnet, tied to Russia's Sandworm, from Asus and WatchGuard routers
TechCrunchZack Whittaker
Context & Ripple Effects
Cyclops Blink had been publicly identified weeks earlier as Sandworm-linked malware circulating for nearly three years. The March operation turns that attribution into intervention, following the FBI’s earlier court-ordered seizure of VPNFilter infrastructure designed to prevent a router botnet from reactivating after reboots.
The case places Asus and WatchGuard network hardware in a recurring enforcement focus: compromised routers can supply a durable operational layer for state-linked groups rather than merely serving as endpoints.
First-order effects
The FBI’s court-authorized cutoff deprives Sandworm’s Cyclops Blink operation of the servers used to control infected Asus and WatchGuard routers.
Asus and WatchGuard customers with affected routers lose the botnet’s active command channel immediately, while the vendors face a more urgent remediation burden for deployed devices.
Second-order effects
The operation reinforces infrastructure seizure as a response to router botnets, a model the FBI later used in the Volt Typhoon disruption involving Cisco and Netgear devices.
Router makers and enterprise customers face pressure to treat remote-management exposure and device lifecycle support as security issues, since attackers can build control networks from installed hardware.
Third-order effects
Repeated court-backed botnet disruptions point to a more interventionist model of cyber defense in which US authorities target adversaries’ control infrastructure, not only individual malware infections.
If state-linked groups continue to rely on routers for persistence, network-device security and support lifecycles become more central to national cyber resilience than endpoint-only defenses.
The trend: Law enforcement is increasingly disrupting state-linked cyber operations by severing the control infrastructure embedded in widely deployed network devices.
A decade ago you'd have gotten shouted out of the room for suggesting hacking systems to remove malware. I guess at some point people realized having philosophical debates on ethics doesn't actually stop the bad guys. https://www.justice.gov/...
I recast my earlier incorrect tweet, which stated that compromised devices themselves were targeted by the operation — similar to how the FBI removed backdoors from Exchange servers last year. Apologies for the error.
According to the court order, only about 39% of compromised routers were fixed in the weeks that followed the initial advisory on February 23, which the DOJ used to justify the mass-removal operation (https://t.co/...). Here's the full court order: https://www.documentcloud.org/ …
The real fight against Russian cyber aggression looks more like this story by @zackwhittaker than the “cyberwar” predicted elsewhere https://techcrunch.com/...
FBI said it mass-removed the “Cyclops Blink” malware from devices but that device owners still need to take action to prevent re-infection. Cyclops Blink is part of a huge botnet run by Sandworm, known for launching destructive cyberattacks. https://techcrunch.com/...
The DOJ said that together with international partners it has disrupted a botnet operated by Russian's GRU military intelligence service. No names or confirmation yet, but this appears to have been Sandworm's Cyclops Blink (?) Presser from an hour ago: https://www.justice.gov/liv…