Explorer

Cyclops Blink Russian State-Sponsored Botnet Attacking Asus Routers In India, US, Canada And More Countries

Cyclops Blink which has been identified as a Russian state-sponsored botnet linked to the Sandworm or Voodoo Bear advanced persistent threat (APT) group is now targetting Asus home Wi-Fi routers.

New Delhi: Cyclops Blink which has been identified as a notorious Russian state-sponsored botnet linked to the Sandworm or Voodoo Bear advanced persistent threat (APT) group is now targetting Asus home Wi-Fi routers, according to Japanese antivirus company Trend Micro. The Russian botnet has been lurking around since at least 2019 and has been linked to the 2015 attack against Ukraine's power grid as well as disruptions in the Republic of Georgia and at the 2018 Olympics. Infected devices have been detected in India, the US, Italy, Canada, and even Russia.

"Cyclops Blink, an advanced modular botnet that is reportedly linked to the Sandworm or Voodoo Bear APT group, has recently been used to target WatchGuard Firebox devices according to an analysis performed by the UK’s National Cyber Security Centre (NCSC). We acquired a variant of the Cyclops Blink malware family that targets Asus routers," Trend Micro recently said in a statement.

"This report discusses the technical capabilities of this Cyclops Blink malware variant and includes a list of more than 150 current and historical command-and-control (C&C) servers of the Cyclops Blink botnet. Our data also shows that although Cyclops Blink is a state-sponsored botnet, its C&C servers and bots affect WatchGuard Firebox and Asus devices that do not belong to critical organisations or those that have an evident value on economic, political, or military espionage," the antivirus firm added.

The security researchers at the Japanese antivirus firm mentioned that it is likely that the Cyclops Blink botnet’s main purpose is to build an infrastructure for further attacks on high-value targets and not harming right now. The Cyclops Blink malware was first spotted in February infecting Firebox small-business network-security appliances made by WatchGuard. 

Meanwhile, Asus was made aware of the attacks and had earlier said in a statement on its Product Security Advisory page that the company is also looking into Cyclops Blink and taking remediation measures.

Top Headlines

Bloody Monday On Dalal Street: Sensex Crashes 1,000 Points Amid US-Iran Tensions, Nifty Over 1% Down
Bloody Monday On Dalal Street: Sensex Crashes 1,000 Points Amid US-Iran Tensions, Nifty Over 1% Down
Israel Launches Strikes Across Lebanon After Hezbollah Fires Rockets And Drones
Israel Launches Strikes Across Lebanon After Hezbollah Fires Rockets And Drones
PM Modi Speaks With Israel’s Netanyahu Amid Rising West Asia Tensions
PM Modi Speaks With Israel’s Netanyahu Amid Rising West Asia Tensions
Israel-Iran War: Trump Says ‘48 Iranian Leaders Killed In One Strike’, Claims New Leadership Ready To Talk
Trump Says 48 Iranian Leaders Killed, 9 Warships Sunk; Claims New Leadership Ready For Talks

Videos

Breaking News: Netanyahu Holds High-Level War Room Meeting Amid Iran Conflict
Breaking News: Hezbollah Launches Rockets at Israel in Support of Iran
War Alert: Donald Trump Issues Strong Warning During Iran War
Breaking News: Iranian Supreme Leader Killed in Attack
Emergency Alert: International Atomic Energy Agency Calls Urgent Meeting

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget