{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/network-edge/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["IRON VIKING"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Firewall Management Center","Firebox","XTM"],"_cs_severities":["high"],"_cs_tags":["cyclops-blink","iron-viking","linux","modular-malware","network-edge"],"_cs_type":"threat","_cs_vendors":["Cisco","WatchGuard"],"content_html":"\u003cp\u003eIn August 2026, researchers identified a sophisticated 64-bit Linux modular implant named 'timezone_check' operating on Cisco Firewall Management Center (FMC) appliances. Attributed to the Russia-based IRON VIKING (also known as Sandworm) threat group, this variant represents a significant evolution from the 2022 firmware-based Cyclops Blink implants. By leveraging standard System V (SysV) initialization scripts for persistence instead of vendor-specific firmware modifications, the malware achieves broader compatibility across Linux-based network-edge devices.\u003c/p\u003e\n\u003cp\u003eThe architecture centers on a 'controller' process that masquerades as a legitimate Linux kernel thread '[kworker/0:1]' to evade casual inspection. This controller coordinates five child-process worker modules that perform host reconnaissance, file exfiltration, arbitrary payload execution, network discovery, and packet surveillance. The ability to load and register new modules at runtime allows the threat actors to maintain persistent remote access and transform compromised network-edge appliances into versatile platforms for intelligence collection and lateral movement within sensitive management environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial infection via exploitation of undisclosed vulnerability on the network-edge appliance.\u003c/li\u003e\n\u003cli\u003eDeployment of the 64-bit ELF executable 'timezone_check' to the target system.\u003c/li\u003e\n\u003cli\u003eExecution of the malware which immediately initiates a masquerading process named '[kworker/0:1]' to hide in process listings.\u003c/li\u003e\n\u003cli\u003eModification of Linux iptables (via libiptc or the iptables utility) to permit outbound TCP traffic on ports 43856 and 49172.\u003c/li\u003e\n\u003cli\u003eEstablishment of persistence via standard SysV init scripts to ensure the implant survives system reboots.\u003c/li\u003e\n\u003cli\u003eController initialization, which synchronizes the shared status structure and IPC channels with five worker modules.\u003c/li\u003e\n\u003cli\u003eRegular execution of module 0x08 for host and network reconnaissance, including the potential theft of sensitive files like /etc/shadow.\u003c/li\u003e\n\u003cli\u003eDeployment of module 0x0F for C2-orchestrated file transfers and the execution of additional modular payloads to expand mission objectives.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe compromise of network-edge appliances such as Cisco FMC provides attackers with deep visibility into internal network segments, access to administrative management interfaces, and the potential for intercepting traffic across critical segments. Successful exploitation allows for persistent intelligence collection, lateral movement into internal systems, and the ability to exfiltrate configurations and credentials from the device itself. Given the role of these appliances in securing infrastructure, the impact extends to a complete loss of confidentiality and integrity within the managed environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHunt for the masquerading process name '[kworker/0:1]' in process listings, as legitimate kernel threads typically appear in brackets but are managed by the kernel, not as standalone ELF binaries.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized modifications to iptables rules, specifically those permitting traffic on non-standard ports 43856 and 49172.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect suspicious process execution masquerading as kernel threads.\u003c/li\u003e\n\u003cli\u003eInspect persistent startup directories for non-standard SysV init scripts added without a clear administrative change record.\u003c/li\u003e\n\u003cli\u003eRestrict outbound network access from internal infrastructure components to untrusted external IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-12T13:07:11Z","date_published":"2026-09-11T18:53:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cyclops-blink-linux/","summary":"The IRON VIKING threat group has deployed an updated modular Cyclops Blink variant on Cisco Firewall Management Center devices, using SysV persistence and masquerading as a kernel thread to conduct reconnaissance and remote operations.","title":"Cyclops Blink Modular Linux Implant Targeting Network-Edge Appliances","url":"https://feed.craftedsignal.io/briefs/2026-09-cyclops-blink-linux/"}],"language":"en","title":"CraftedSignal Threat Feed - Network-Edge","version":"https://jsonfeed.org/version/1.1"}