# T1495 Firmware Corruption

> As of 2026-10-05, T1495 (Firmware Corruption) appears in 21 tracked threats, first reported 2026-02-02 and most recently 2026-09-09, with linked actors including Static Tundra, FSB Center 16, Sandworm; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 21 (10 critical, 8 high, 2 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-09
- **Threat actors:** 7
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1495
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1495/

## Activity timeline

T1495 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-09. The busiest month was 2026-07 with 10 reports, and 21 of the 21 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1495 Firmware Corruption is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 21 of 2623 tracked threats (0.8%) to it; by severity that is 10 critical, 8 high, 2 medium.

Threats that use T1495 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (13 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (11 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (10 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (10 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1495; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (3), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (2), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (2), [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1495.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1495, per MITRE ATT&CK.

- Firmware — Firmware Modification

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1

## Tracked threats

21 tracked threats use T1495.

- [Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector](https://intel.threadlinqs.com/threat/TL-2026-2425) — high — 2026-09-09
- ["Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)](https://intel.threadlinqs.com/threat/TL-2026-2039) — medium — 2026-08-17
- [ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish…](https://intel.threadlinqs.com/threat/TL-2026-1883) — critical — 2026-08-05
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — critical — 2026-08-01
- [Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Grids](https://intel.threadlinqs.com/threat/TL-2026-1598) — high — 2026-07-21
- [11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1340) — high — 2026-07-14
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — high — 2026-07-14
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…](https://intel.threadlinqs.com/threat/TL-2026-1279) — critical — 2026-07-13
- [VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…](https://intel.threadlinqs.com/threat/TL-2026-1261) — medium — 2026-07-13
- [Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…](https://intel.threadlinqs.com/threat/TL-2026-1251) — high — 2026-07-13
- [Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)](https://intel.threadlinqs.com/threat/TL-2026-1250) — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — high — 2026-07-11
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — critical — 2026-07-10
- [usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…](https://intel.threadlinqs.com/threat/TL-2026-0876) — high — 2026-06-19
- [usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices](https://intel.threadlinqs.com/threat/TL-2026-0871) — high — 2026-06-19
- [usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…](https://intel.threadlinqs.com/threat/TL-2026-0860) — critical — 2026-06-18
- [CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box…](https://intel.threadlinqs.com/threat/TL-2026-0269) — critical — 2026-03-22
- [RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert…](https://intel.threadlinqs.com/threat/TL-2026-0163) — critical — 2026-03-02
- [Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper](https://intel.threadlinqs.com/threat/TL-2026-0014) — critical — 2026-02-02
- [Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0004) — critical — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1495, most frequent first.

- [CVE-2004-2687](https://intel.threadlinqs.com/cve/CVE-2004-2687)
- [CVE-2011-2523](https://intel.threadlinqs.com/cve/CVE-2011-2523)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-12108](https://intel.threadlinqs.com/cve/CVE-2019-12108)
- [CVE-2019-12109](https://intel.threadlinqs.com/cve/CVE-2019-12109)
- [CVE-2019-12110](https://intel.threadlinqs.com/cve/CVE-2019-12110)
- [CVE-2019-12111](https://intel.threadlinqs.com/cve/CVE-2019-12111)
- [CVE-2020-28951](https://intel.threadlinqs.com/cve/CVE-2020-28951)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2025-8321](https://intel.threadlinqs.com/cve/CVE-2025-8321)
- [CVE-2026-21902](https://intel.threadlinqs.com/cve/CVE-2026-21902)
- [CVE-2026-23670](https://intel.threadlinqs.com/cve/CVE-2026-23670)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1495 (SPL 8, KQL 10, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1495
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
