

WatchGuard Firewalls: Cyclops Blink Botnet (English Version)
source link: https://blog.boll.ch/watchguard-firewalls-cyclops-blink-botnet/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

WatchGuard Firewalls: Cyclops Blink Botnet (English Version)
According to current information, a limited number (~1%) of WatchGuard firewalls have been infected by a state-sponsored botnet called Cyclops Blink. Although there is currently no evidence of data exfiltration, it is possible that data from the firewalls has been compromised.
Blog article in German can be found here: https://blog.boll.ch/watchguard-firewalls-cyclops-blink-botnet-befall/
Official statement
https://detection.watchguard.com/
Blog with additional information
https://www.watchguard.com/wgrd-news/blog/important-detection-and-remediation-actions-cyclops-blink-state-sponsored-botnet
Cyclops Blink FAQ
https://techsearch.watchguard.com/
1. Is my firewall affected?
WatchGuard provides several ways to find an infestation of the botnet software on the firewalls:
Cyclops Blink Web Detector (online)
On the website https://detection.watchguard.com/Detector you can upload a support.tgz of the firewall and check for botnet infestation.

WatchGuard System Manager Cyclops Blink Detector
In the latest WSM version 12.7.2 update 2 (downloadable now) there is a Cyclops Blink Detector:

Download WSM Version 12.7.2 Update 2
https://cdn.watchguard.com/SoftwareCenter/Files/WSM/12_7_2_U2/wsm_12_7_2_U2.exe
WatchGuard Cloud Cyclops Blink Detector
Firewalls added to the WatchGuard Cloud also have a Cyclops Blink Detector:

2a. My firewall is not affected
Even if your firewall is not affected, you should implement the following advice as soon as possible:
Install the latest firmware
Here you can find the latest firmware:
https://software.watchguard.com/SoftwareHome
Close the management ports from the Internet
WatchGuard assumes that the malware could be installed through the management ports.
https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA10H000000XeAtSAK&lang=en_US
Changing administrator password
Administrator passwords should be changed regularly.
2b. My firewall is affected
Depending on the type of management, it may be necessary to completely reset and rebuild the firewall, as the malware may take root in the configuration and software:
Locally managed Firebox via WSM or Fireware WebUI
Cyclops Blink: Remediate a Locally-Managed Firebox
WatchGuard Cloud managed Fireboxes
Cyclops Blink: Remediate a Cloud-Managed Firebox
Firebox Cloud
Cyclops Blink: Remediate Firebox Cloud
FireboxV / XTMv
Cyclops Blink: Remediate FireboxV and XTMv
Fireboxes managed by the management server
Cyclops Blink: Remediate a Firebox Managed by WSM Management Server
625 total views, 2 views today
Leave a Reply Cancel reply
Comment *
Name *
Email *
Website
Save my name, email, and website in this browser for the next time I comment.
Recommend
-
7
Wednesday, 14 April 2021 12:59 Soft Solutions offers WatchGuard subscriptions By Stephen Withers ...
-
11
Friday, 25 June 2021 16:22 New WatchGuard research reveals traditional anti-malware solutions miss nearly 75% of threats By WatchGuard Technologies ...
-
7
美、英发现新的僵尸网络恶意程序 Cyclops Blink-51CTO.COM 美、英发现新的僵尸网络恶意程序 Cyclops Blink 2022-02-25 13:31:10 黑客针对 WatchGuard 设备的 Firebox 软件更新程序进行了反向工...
-
3
华硕警告针对路由器的 Cyclops Blink 恶意软件攻击-51CTO.COM 华硕警告针对路由器的 Cyclops Blink 恶意软件攻击 作者:Zicheng 2022-03-18 13:15:30 ...
-
12
Cyclops Blink botnet is attacking and actively exploiting Asus routers Russia is hijacking Asus routers By Sayak Biswas March...
-
8
MUM'S THE WORD — WatchGuard failed to explicitly disclose critical flaw exploited by Russian hackers Silently fixed authentication bypass remained a secret even after it was u...
-
6
WatchGuard Firewalls: Cyclops Blink Botnet Befall (Deutsche Version)Gemäss aktuellen Informationen sind eine begrenzte Anzahl (~1%) von WatchGuard Firewalls von einem staatlich gesponserten Botnet namens “Cyclops Blink” befallen...
-
5
Thursday, 30 March 2023 12:52 Endpoint ransomware surges: WatchGuard By Stephen Withers ...
-
4
Cyclops raises $6.4M in seed funding to launch AI-powered cybersecurity search platform
-
3
Support is great. Feedback is even better."Thanks for checking us out ❤️ Feel free to test our MVP at no cost. Instructions on setting up Cyclops in under 5 minutes can be found on our website. We would love to hear feedback and sugg...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK