Activity timeline
T1495 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1495 Firmware Corruption is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 10 critical, 8 high, 2 medium.
Threats that use T1495 most often also use T1685 Disable or Modify Tools (13 threats), T1082 System Information Discovery (11 threats), T1005 Data from Local System (10 threats), T1068 Exploitation for Privilege Escalation (10 threats), T1078 Valid Accounts (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1495; the most frequent are Static Tundra (3), FSB Center 16 (2), Sandworm (2), APT44 (1), INC Ransom (1).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1495.
Data sources
Telemetry that can reveal T1495, per MITRE ATT&CK.
- Firmware — Firmware Modification
Threat actors using it
Tracked threats
21 tracked threats use T1495.
- Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connectorhigh
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)medium
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…critical
- CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Executioncritical
- Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Gridshigh
- 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)high
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)high
- NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…critical
- VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…medium
- Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…high
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flashhigh
- CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)critical
- usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…high
- usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) deviceshigh
- usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…critical
- CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box…critical
- RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert…critical
- Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWipercritical
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructurecritical
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1495 (SPL 8, KQL 10, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.