/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

In a court-authorized March operation, the FBI cut off the servers of the Cyclops Blink botnet, tied to Russia's Sandworm, from Asus and WatchGuard routers

TechCrunch Zack Whittaker

Context & Ripple Effects

Cyclops Blink had been publicly identified weeks earlier as Sandworm-linked malware circulating for nearly three years. The March operation turns that attribution into intervention, following the FBI’s earlier court-ordered seizure of VPNFilter infrastructure designed to prevent a router botnet from reactivating after reboots.

The case places Asus and WatchGuard network hardware in a recurring enforcement focus: compromised routers can supply a durable operational layer for state-linked groups rather than merely serving as endpoints.

First-order effects

  • The FBI’s court-authorized cutoff deprives Sandworm’s Cyclops Blink operation of the servers used to control infected Asus and WatchGuard routers.
  • Asus and WatchGuard customers with affected routers lose the botnet’s active command channel immediately, while the vendors face a more urgent remediation burden for deployed devices.

Second-order effects

  • The operation reinforces infrastructure seizure as a response to router botnets, a model the FBI later used in the Volt Typhoon disruption involving Cisco and Netgear devices.
  • Router makers and enterprise customers face pressure to treat remote-management exposure and device lifecycle support as security issues, since attackers can build control networks from installed hardware.

Third-order effects

  • Repeated court-backed botnet disruptions point to a more interventionist model of cyber defense in which US authorities target adversaries’ control infrastructure, not only individual malware infections.
  • If state-linked groups continue to rely on routers for persistence, network-device security and support lifecycles become more central to national cyber resilience than endpoint-only defenses.

The trend: Law enforcement is increasingly disrupting state-linked cyber operations by severing the control infrastructure embedded in widely deployed network devices.

Discussion

  • @malwaretechblog Marcus Hutchins on x
    A decade ago you'd have gotten shouted out of the room for suggesting hacking systems to remove malware. I guess at some point people realized having philosophical debates on ethics doesn't actually stop the bad guys. https://www.justice.gov/...
  • @b_judah Ben Judah on x
    Is Russia also losing the cyberwar? https://www.nytimes.com/...
  • @ericgarland Eric Garland on x
    AMAZING: DOJ indicts *Russian military intelligence* for running a botnet 🤣🔥⚖️ https://www.justice.gov/...
  • @zackwhittaker Zack Whittaker on x
    I recast my earlier incorrect tweet, which stated that compromised devices themselves were targeted by the operation — similar to how the FBI removed backdoors from Exchange servers last year. Apologies for the error.
  • @zackwhittaker Zack Whittaker on x
    According to the court order, only about 39% of compromised routers were fixed in the weeks that followed the initial advisory on February 23, which the DOJ used to justify the mass-removal operation (https://t.co/...). Here's the full court order: https://www.documentcloud.org/ …
  • @profwoodward Alan Woodward on x
    The real fight against Russian cyber aggression looks more like this story by @zackwhittaker than the “cyberwar” predicted elsewhere https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    FBI said it mass-removed the “Cyclops Blink” malware from devices but that device owners still need to take action to prevent re-infection. Cyclops Blink is part of a huge botnet run by Sandworm, known for launching destructive cyberattacks. https://techcrunch.com/...
  • @campuscodi Catalin Cimpanu on x
    The DOJ said that together with international partners it has disrupted a botnet operated by Russian's GRU military intelligence service. No names or confirmation yet, but this appears to have been Sandworm's Cyclops Blink (?) Presser from an hour ago: https://www.justice.gov/liv…