SYNful Knock

MITRE ATT&CK: S0519 View on attack.mitre.org

Aliases: SYNful Knock

First seen
2015-09-15 00:00:00
Malware type
backdoor, rootkit
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 15:28:13

Targeted industries: government-and-public-sector

Targeted regions: country_code:us country_code:cn country_code:ru

Context

SYNful Knock is a stealthy modification of the operating system of network devices that can be used to maintain persistence within a victim's network and provide new capabilities to the adversary.

Detection coverage

  • 1 Sigma rules

Malware & tools used

  • Patch System Image (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Network Device Authentication (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0519 (report)
  • blogs.cisco.com — Evolution Of Attacks On Cisco Ios Devices (report)
  • cloud.google.com — Synful Knock Acis (report)

External references