The US Justice Department in March carried out an operation that successfully removed malware known as “Cyclops Blink” from vulnerable internet-connected firewall devices, the department announced Wednesday. The operation disrupted the control the Russian Federation’s Main Intelligence Directorate (GRU) had over a global botnet of thousands of infected devices.
The Cyclops Blink Malware specifically targeted WatchGuard and Asus network devices. A threat actor known as Sandworm (which the US government previously attributed to the GRU) used the malware for command and control of the underlying botnet. By disabling the command and control mechanism, the Justice Department was able to sever Sandworm from the network of bots.