← Back to Feed
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
September 14, 2026 · Dark Reading · Severity: HIGH
Russian state-sponsored threat actor Sandworm is chaining multiple Cisco vulnerabilities to deploy the Cyclops Blink botnet across critical infrastructure, using compromised network devices as persistent backdoors. 📌 **Analyst Note:** Cyclops Blink's return confirms that botnet takedowns are only temporarily effective — operators rebuild with improved capabilities. Organizations must assume persistent re-emergence and build behavioral detection rather than relying on known infrastructure indicators.
Key Takeaways
- Russian state-sponsored group Sandworm is chaining multiple Cisco vulnerabilities to deploy the Cyclops Blink botnet across critical infrastructure.
- The campaign uses unpatched Cisco devices as initial access points to establish persistent backdoor access via Cyclops Blink malware.
- Organizations should urgently audit Cisco devices for the specific CVEs associated with this Sandworm campaign and apply available patches.