System Firmware

T1542.001

Sub-technique of T1542 Pre-OS Boot.View on attack.mitre.org

About this technique

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.

Detection rules6

Rules on DetectionCode tagged with T1542.001.

Sigma2

RuleLevelLog source
UEFI Persistence Via Wpbbin - FileCreationhighwindows / file_event
UEFI Persistence Via Wpbbin - ProcessCreationhighwindows / process_creation

Splunk4

RuleTypeRiskData source
Linux EFI Bootloader File DeletionTTPNULLSysmon for Linux EventID 11
Linux Possible Bootloader ModificationTTPNULLSysmon for Linux EventID 1
Windows BootLoader InventoryHuntingNULL
Windows Suspicious File in EFI VolumeTTPNULLSysmon EventID 11

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples3

Software3

Used byProcedure example
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

MalwareTrojan.Mebromi

Trojan.Mebromi performs BIOS modification and can download and execute a file as well as protect itself from removal.

References3

  1. About UEFI Open source
    UEFI Forum. (n.d.). About UEFI Forum. Retrieved January 5, 2016.
  2. Wikipedia BIOS Open source
    Wikipedia. (n.d.). BIOS. Retrieved January 5, 2016.
  3. Wikipedia UEFI Open source
    Wikipedia. (2017, July 10). Unified Extensible Firmware Interface. Retrieved July 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.