Component Firmware

December 5, 2023 ยท View on GitHub

ID F0009
Objective(s) Impact, Persistence, Defense Evasion
Related ATT&CK Techniques Pre-OS Boot: Component Firmware (T1542.002)
Impact Type Breach
Version 2.0
Created 1 August 2019
Last Modified 12 June 2023

Component Firmware

Malware may overwrite the flash memory of firmware outside of the main system firmware or BIOS [1]. Methods related to malware (extending ATT&CK's definitions) are below.

See ATT&CK: Pre-OS Boot: Component Firmware (T1542.002).

Methods

NameIDDescription
Router FirmwareF0009.001Cisco routers can have their firmware images modified in order to maliciously infect and persist on end-user machines in a network. This is accomplished by using default or acquired credentials to gain access to a router and to install a backdoor. The implant resides within a modified Cisco IOS image and, when loaded, maintains its persistence in the environment, even after a system reboot. However, any further modules loaded by the attacker will only exist in the router's volatile memory and will not be available for use after reboot. Known affected hardware includes Cisco routers 1841, 2811, and 3825.

Use in Malware

NameDateMethodDescription
SYNful Knock2015F0009.001SYNful Knock is a stealthy modification of the router's firmware image that can be used to maintain persistence within a victim's network. [1]

References

[1] https://www.mandiant.com/resources/synful-knock-acis