← Back to Feed

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

September 14, 2026 · Dark Reading · Severity: HIGH

Russian state-sponsored threat actor Sandworm is chaining multiple Cisco vulnerabilities to deploy the Cyclops Blink botnet across critical infrastructure, using compromised network devices as persistent backdoors. 📌 **Analyst Note:** Cyclops Blink's return confirms that botnet takedowns are only temporarily effective — operators rebuild with improved capabilities. Organizations must assume persistent re-emergence and build behavioral detection rather than relying on known infrastructure indicators.

Key Takeaways

  • Russian state-sponsored group Sandworm is chaining multiple Cisco vulnerabilities to deploy the Cyclops Blink botnet across critical infrastructure.
  • The campaign uses unpatched Cisco devices as initial access points to establish persistent backdoor access via Cyclops Blink malware.
  • Organizations should urgently audit Cisco devices for the specific CVEs associated with this Sandworm campaign and apply available patches.
☕ Buy a Coffee