ATT&CKSoftwareSYNful Knock

SYNful Knock

S0519

Malware.View on attack.mitre.org

About this malware

SYNful Knock is a stealthy modification of the operating system of network devices that can be used to maintain persistence within a victim's network and provide new capabilities to the adversary.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1205
Traffic Signaling

SYNful Knock can be sent instructions via special packets to change its functionality. Code for new functionality can be included in these messages.

T1556.004
Network Device Authentication

SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device.

T1601.001
Patch System Image

SYNful Knock is malware that is inserted into a network device by patching the operating system image.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Cisco Synful Knock Evolution Open source
    Graham Holmes. (2015, October 8). Evolution of attacks on Cisco IOS devices. Retrieved October 19, 2020.
  2. Mandiant - Synful Knock Open source
    Bill Hau, Tony Lee, Josh Homan. (2015, September 15). SYNful Knock - A Cisco router implant - Part I. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.