Firmware Corruption
Description
Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system.(Citation: Symantec Chernobyl W95.CIH) Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards. In general, adversaries may manipulate, overwrite, or corrupt firmware in order to deny the use of the system or devices. For example, corruption of firmware responsible for loading the operating system for network devices may render the network devices inoperable.(Citation: dhs_threat_to_net_devices)(Citation: cisa_malware_orgs_ukraine) Depending on the device, this attack may also result in [Data Destruction](https://attack.mitre.org/techniques/T1485).
Mapped SPARTA techniques
6 techniques
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
T1495 'Firmware Corruption' addresses permanent partial impairment via firmware overwrite/corruption (rendering devices inoperable or with reduced capability); SPARTA IMP-0004 'Degradation' is the parent-level spacecraft equivalent (permanently partially impair use of subsystems via firmware-level damage). Tactic and activity align directly.
T1495 'Firmware Corruption' covers permanent firmware-level damage that renders devices inoperable; SPARTA IMP-0005 'Destruction' includes firmware/component destruction as a destruction mode. Tactic-aligned moderate (T1485 is the dominant primary anchor for total destruction).
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, mitre-attack-enterprise T1495.