Advisory AA22-054A: Cyclops Blink ran undetected for thirty-two months

Four Agencies, One Date, One Version Number

The primary document is a joint advisory titled “New Sandworm malware Cyclops Blink replaces VPNFilter,” published as Version 1.0 on February 23, 2022. Four agencies co-authored it: the UK’s National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI). It carries the CISA identifier AA22-054A and bears a “Crown Copyright 2022” notice.

The NCSC published a companion Malware Analysis Report on the same date. WatchGuard, manufacturer of the confirmed victim devices, coordinated release of its own four-step detection and remediation plan to coincide with the advisory.

Two earlier industry documents provide the prior record. In May 2018, Cisco Talos publicly documented VPNFilter, the predecessor malware; the US Department of Justice announced disruption of its botnet that same month and linked the activity to Sandworm. In January 2021, TrendMicro recorded declining but still-active command-and-control traffic from residual VPNFilter infections, nearly three years after that initial exposure.

What Was Running Before Anyone Said So

The advisory states that Cyclops Blink was deployed on compromised network devices no later than June 2019. VPNFilter had been publicly exposed and its botnet disrupted in May 2018. The gap between those two dates is fourteen months, a figure the advisory states explicitly.

From June 2019 to February 23, 2022 is approximately thirty-two months. That arithmetic comes directly from the dates the document supplies. The advisory does not address why the period between first deployment and public acknowledgment was that long.

The Technical Record, As Written

The advisory and the companion NCSC Malware Analysis Report describe Cyclops Blink as a modular framework, compiled as a Linux ELF executable for PowerPC big-endian architecture. Its core functions, as the advisory states them, are beaconing device information to remote command-and-control servers, downloading and executing files, and accepting new functional modules during live operation without requiring a restart.

The malware embeds itself within modified firmware images. The advisory states it survives both device reboots and the standard firmware update process, meaning a routine update does not remove it. Compromised devices are organized into clusters, each with its own command-and-control IP addresses and ports. Communications are encrypted using individually generated TLS keys and certificates, with message content encrypted under AES-256-CBC. Sandworm operators connect to the command-and-control layer through Tor.

Every confirmed victim instance involved a WatchGuard firewall appliance. The advisory specifies that only WatchGuard devices reconfigured from manufacturer defaults to expose their remote management interface externally were found to be susceptible.

Sandworm: What the Agencies Concluded and on What Basis

The four agencies jointly attributed Cyclops Blink to Sandworm, also designated Voodoo Bear, which they attribute to the Russian GRU’s Main Centre for Special Technologies (GTsST), military unit 74455. The advisory presents this as established, not a preliminary assessment.

The agencies ground that conclusion in a prior record: Sandworm has been attributed to the December 2015 BlackEnergy attacks on Ukrainian electricity infrastructure; a follow-on Industroyer attack in December 2016; the NotPetya campaign on June 27, 2017; disruption operations against the 2018 Winter Olympics; and an attack against Georgia on October 28, 2019. A US indictment of six GRU Unit 74455 officers was filed in October 2020.

The agencies concluded that Sandworm deliberately retired VPNFilter after its 2018 exposure and constructed Cyclops Blink as a stealthier replacement. The advisory uses the word “indiscriminate” to characterize the geographic spread of deployment. Separately, the NCSC stated on February 23, 2022 that the advisory was “a routine advisory and not directly linked to the situation in Ukraine.” That is an NCSC claim made alongside the document, not a finding of the joint advisory itself.

Staging Infrastructure, Not Primary Targets

The advisory’s specific interpretive assessment is that compromised devices are most likely being used as staging infrastructure for subsequent operations, rather than because the organizations running them are themselves of interest. Infection does not mean the affected organization is the primary intended target. No confirmed victim is identified in the record as a deliberate primary target.

A large-scale compromise of network edge devices, organized into clusters with encrypted and Tor-anonymized operator communications, is consistent with construction of a durable infrastructure platform for future use. The advisory’s framing of the campaign as infrastructure compromise rather than targeted espionage follows directly from that architecture.

What the Record Does Not Settle

Three things remain formally open, and the advisory names them itself.

The scope of compromised devices beyond WatchGuard hardware is not established. The advisory states Sandworm is likely capable of compiling Cyclops Blink for other architectures, but no confirmed cases on non-WatchGuard hardware appear in the document.

The infection vector is not confirmed. The advisory describes it as “most likely” involving an externally available service, the document’s own phrasing, signaling an assessment rather than a determination.

The indicators of compromise are explicitly described in the advisory as non-exhaustive and do not define the outer boundary of the deployment. What the infrastructure was used to do against which specific targets is not answered anywhere in the document.

WatchGuard reported that approximately 1% of its active firewall appliances were affected. The FBI executed a court-authorized disruption operation, concluded before April 6, 2022, copying and removing malware from identified command-and-control devices and severing the command-and-control mechanism from bot devices worldwide. That operation did not extend to direct access of individual victim devices, and the FBI noted that by the time of the operation a majority of originally compromised bot devices remained infected despite remediation guidance having been publicly available since February 23, 2022.