Firmware Corruption

T1495

Technique.View on attack.mitre.org

About this technique

Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.

In general, adversaries may manipulate, overwrite, or corrupt firmware in order to deny the use of the system or devices. For example, corruption of firmware responsible for loading the operating system for network devices may render the network devices inoperable. Depending on the device, this attack may also result in Data Destruction.

Detection rules1

Rules on DetectionCode tagged with T1495.

Sigma1

RuleLevelLog source
Cisco Denial of Servicemediumcisco / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples3

Software2

Used byProcedure example
MalwareBad Rabbit

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.

MalwareTrickBot

TrickBot module "Trickboot" can write or erase the UEFI/BIOS firmware of a compromised device.

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations.

References3

  1. Symantec Chernobyl W95.CIH Open source
    Yamamura, M. (2002, April 25). W95.CIH. Retrieved April 12, 2019.
  2. cisa_malware_orgs_ukraine Open source
    CISA. (2022, April 28). Alert (AA22-057A) Update: Destructive Malware Targeting Organizations in Ukraine. Retrieved July 29, 2022.
  3. dhs_threat_to_net_devices Open source
    U.S. Department of Homeland Security. (2016, August 30). The Increasing Threat to Network Infrastructure Devices and Recommended Mitigations. Retrieved July 29, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.