Detailedlikelihood: Lowseverity: Very HighStable

CAPEC-638Altered Component Firmware

Abstraction
Detailed
Status
Stable
Likelihood
Low
Severity
Very High

Description

An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard Disk Drives (HDD), with the goal of executing malicious code from within the component's Master Boot Record (MBR). Conducting this type of attack entails the adversary infecting the target with firmware altering malware, using known tools, and a payload. Once this malware is executed, the MBR is modified to include instructions to execute the payload at desired intervals and when the system is booted up. A successful attack will obtain persistence within the victim system even if the operating system is reinstalled and/or if the component is formatted or has its data erased.

MITRE ATT&CK crosswalk· 1

T1542.002: Pre-OS Boot:Component Firmware

Related attack patterns· 1

CAPEC-452 (ChildOf)

Related to1

TypeTargetConfidenceTier
SubTechniqueComponent Firmwaret1542.002100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Infected Hardware
Sub-technique
Component Firmware
CAPEC
Malicious Hardware Update
CAPEC
Flash Memory Attacks
CAPEC
Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities
CAPEC
Altered Installed BIOS
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.