The UK and the US identify “Cyclops Blink”, botnet malware tied to the Russian-backed Sandworm hacking group that has been circulating for almost three years
The Russian government's Sandworm group uses previously unseen Cyclops Blink. — Hackers for one of Russia's …
Context & Ripple Effects
Cyclops Blink emerged after a run of public Sandworm activity: US agencies had already tied the group to the GRU and warned of its exploitation of an Exim flaw, while France reported a multiyear breach of entities using Centreon software. The UK-US identification adds a distinct botnet to that record of long-running access and exploitation.
The identification also became operationally consequential: the FBI later cut off Cyclops Blink’s command servers from affected Asus and WatchGuard routers, turning attribution into a coordinated disruption effort.
First-order effects
- UK and US defenders can treat Cyclops Blink as a Sandworm-linked threat rather than an unattributed malware campaign, focusing response on the botnet’s presence and infrastructure.
- Asus and WatchGuard router owners were directly affected by the subsequent FBI operation that severed the botnet’s server connections.
Second-order effects
- The FBI disruption raises the cost of maintaining router-based botnet infrastructure for Sandworm, requiring the group to replace access paths or command-and-control systems.
- Publicly linking Cyclops Blink to the same actor previously associated with GRU-linked attacks on Georgia gives national cyber authorities a common basis for coordinating defensive messaging and response.
Third-order effects
- The sequence points to a more interventionist model of state cyber defense in which public attribution is paired with legal action against botnet infrastructure, rather than relying only on victim-led remediation.
- Sandworm’s record—from exploitation of widely used mail software to router botnets—suggests that internet-facing enterprise infrastructure will remain a central target set for state-linked access campaigns.
The trend: State cyber agencies are increasingly combining technical attribution with infrastructure disruption against persistent Russia-linked intrusion operations.