System Firmware
Parent: T1693
Description
System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment. When available, the firmware update feature enables vendors to remotely patch bugs and perform upgrades. Device firmware updates are often delegated to the user and may be done using a software update package. It may also be possible to perform this task over the network. An adversary may exploit the firmware update feature on accessible devices to upload malicious or out-of-date firmware. Malicious modification of device firmware may provide an adversary with root access to a device, given firmware is one of the lowest programming abstraction layers.(Citation: Basnight, Zachry, et al.)
Mapped SPARTA techniques
4 techniques
Bootkits reside in system firmware; T1693.001 'System Firmware' addresses adversary modification of system firmware which is the residence layer for bootkit installation. Cross-tactic moderate (T1693 family in persistence/inhibit-response-function/impair-process-control vs SPARTA DE-0008 defense-evasion); ICS doesn't have a specific Bootkit sub-technique.
T1693.001 'System Firmware' addresses adversary modification of system firmware; SPARTA EX-0004 'Compromise Boot Memory' covers boot-memory compromise (bootloader, boot ROM, flash boot images) — equivalent firmware-level activity. Cross-tactic moderate (T1693 family sits in persistence/inhibit-response-function/impair-process-control while SPARTA EX-0004 is execution).
Bootkits reside in system firmware below the OS layer; T1693.001 'System Firmware' addresses adversary modification of system firmware which is the residence layer for bootkit implants. Cross-tactic moderate (T1693 family in persistence/inhibit/impair vs SPARTA EX-0010.04 execution); ICS has no specific Bootkit sub-technique.
SDR reconfiguration (adding subcarriers, changing modulation, scheduling maintenance bursts) is achieved by modifying the SDR's system firmware; T1693.001 'System Firmware' covers this firmware-level reconfiguration. Cross-tactic moderate (persistence/inhibit-response-function/impair-process-control vs exfiltration).
Cite as SafeMode Space, mitre-attack-ics T1693.001.