AIO APEX

Cisco Talos ties Sandworm and Qilin ransomware to the FMC firewall flaws exploited this week

BleepingComputer
Share:
Cisco Talos ties Sandworm and Qilin ransomware to the FMC firewall flaws exploited this week

Cisco Talos has identified three separate threat clusters — including a Russian state-sponsored group and a Qilin ransomware affiliate — exploiting the two Secure Firewall Management Center (FMC) vulnerabilities Cisco confirmed were under active attack earlier this week, resolving the attribution questions left open when the company first disclosed the exploitation.

The clusters, tracked by Talos as UAT-12197, UAT-11823, and UAT-11988, exploited CVE-2026-20079 (the maximum-severity, CVSS 10.0 authentication bypass) and CVE-2026-20316 (a static-credential flaw rated High severity) to deploy web shells, steal credentials, establish reverse shells and proxies, and in some cases install ransomware or nation-state backdoor malware directly onto compromised firewall management infrastructure.

A Qilin ransomware affiliate

Talos attributed one cluster, UAT-11988, with high confidence to affiliates of the Qilin ransomware operation. That group used the static credentials tied to CVE-2026-20316 to access an FMC device, then abused the device's own built-in tools to harvest hostnames, IP addresses, directory listings, Active Directory service account credentials, and MySQL credentials — staging the stolen data in publicly accessible files on the compromised FMC server before downloading it over plain HTTP. The attackers then deployed a Python SOCKS5 proxy and reverse SSH tunnel to maintain internal access before ultimately encrypting endpoints with Qilin ransomware.

A Sandworm-linked APT deploying Cyclops Blink

A second cluster, UAT-11823, was attributed with high confidence to a group whose tooling overlaps with Sandworm — the Russian GRU-linked military intelligence hacking unit known for destructive attacks on critical infrastructure. This group modified a license file on compromised FMC devices to establish a Netcat-based reverse shell, executed as root via a legitimate Cisco utility, before deploying a variant of Cyclops Blink — a modular Linux backdoor previously attributed to Sandworm — that provides persistent access, credential theft, and network traffic interception capability.

What this confirms about the July timeline

The Talos report also resolves a lingering question about the vulnerabilities' exploitation timeline. Cisco disclosed CVE-2026-20316 as actively exploited on July 29 and updated the CVE-2026-20079 advisory with matching indicators of compromise at the time, but stopped short of confirming the authentication bypass flaw was also being actively used. Talos' report now confirms both flaws were exploited, in some cases by the same actors, during the same window — meaning organizations that patched only after the September confirmation may have been exposed for significantly longer than they realized.

Cisco has released hot fixes for both vulnerabilities and says a more comprehensive hardening update addressing additional flaws is coming next week. Given that three independent threat clusters — spanning ransomware and state-sponsored espionage — have already weaponized this vulnerability pair, organizations running on-premises Secure FMC should treat patching as complete only after verifying no indicators of compromise from any of Talos' three tracked clusters are present in their logs. As first reported by BleepingComputer.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: