ATT&CKReferencesMandiant - Synful Knock

Mandiant - Synful Knock

Bill Hau, Tony Lee, Josh Homan. (2015, September 15). SYNful Knock - A Cisco router implant - Part I. Retrieved November 17, 2024.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1205
Traffic Signaling
MalwareSYNful Knock

SYNful Knock can be sent instructions via special packets to change its functionality. Code for new functionality can be included in these messages.

T1556.004
Network Device Authentication
MalwareSYNful Knock

SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device.

T1601.001
Patch System Image
MalwareSYNful Knock

SYNful Knock is malware that is inserted into a network device by patching the operating system image.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.