ATT&CKReferencesNCSC Cyclops Blink February 2022

NCSC Cyclops Blink February 2022

NCSC. (2022, February 23). Cyclops Blink Malware Analysis Report. Retrieved March 3, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareCyclops Blink

Cyclops Blink can upload files from a compromised host.

T1016
System Network Configuration Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.

T1036.005
Match Legitimate Resource Name or Location
MalwareCyclops Blink

Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread. Cyclops Blink has also named RC scripts used for persistence after WatchGuard artifacts.

T1037.004
RC Scripts
MalwareCyclops Blink

Cyclops Blink has the ability to execute on device startup, using a modified RC script named S51armled.

T1041
Exfiltration Over C2 Channel
MalwareCyclops Blink

Cyclops Blink has the ability to upload exfiltrated files to a C2 server.

T1057
Process Discovery
MalwareCyclops Blink

Cyclops Blink can enumerate the process it is currently running under.

T1070.006
Timestomp
MalwareCyclops Blink

Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images.

T1071.001
Web Protocols
MalwareCyclops Blink

Cyclops Blink can download files via HTTP and HTTPS.

T1082
System Information Discovery
MalwareCyclops Blink

Cyclops Blink has the ability to query device information.

T1083
File and Directory Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.

T1105
Ingress Tool Transfer
MalwareCyclops Blink

Cyclops Blink has the ability to download files to target systems.

T1106
Native API
MalwareCyclops Blink

Cyclops Blink can use various Linux API functions including those for execution and discovery.

T1132.002
Non-Standard Encoding
MalwareCyclops Blink

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1140
Deobfuscate/Decode Files or Information
MalwareCyclops Blink

Cyclops Blink can decrypt and parse instructions sent from C2.

T1542.002
Component Firmware
MalwareCyclops Blink

Cyclops Blink has maintained persistence by patching legitimate device firmware when it is downloaded, including that of WatchGuard devices.

T1571
Non-Standard Port
MalwareCyclops Blink

Cyclops Blink can use non-standard ports for C2 not typically associated with HTTP or HTTPS traffic.

T1573.002
Asymmetric Cryptography
MalwareCyclops Blink

Cyclops Blink can encrypt C2 messages with AES-256-CBC sent underneath TLS. OpenSSL library functions are also used to encrypt each message using a randomly generated key and IV, which are then encrypted using a hard-coded RSA public key.

T1584.005
Botnet
GroupSandworm Team

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.

T1686.002
Network Device Firewall
MalwareCyclops Blink

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.