Activity timeline
T1542 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 23 of the 23 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1542 Pre-OS Boot is catalogued by MITRE ATT&CK under the Persistence and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 23 of 2623 tracked threats (0.9%) to it; by severity that is 10 critical, 12 high, 1 medium.
Threats that use T1542 most often also use T1068 Exploitation for Privilege Escalation (15 threats), T1082 System Information Discovery (14 threats), T1685 Disable or Modify Tools (14 threats), T1078 Valid Accounts (10 threats), T1190 Exploit Public-Facing Application (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1542; the most frequent are Chaotic Eclipse (1), INC Ransom (1), INC Ransom - G1032 (1), Lynx (1), Nightmare Eclipse (1).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1542.
Data sources
Telemetry that can reveal T1542, per MITRE ATT&CK.
- Command — Command Execution
- Drive — Drive Modification
- Driver — Driver Metadata
- File — File Creation, File Modification
- Firmware — Firmware Modification
- Network Traffic — Network Connection Creation
- Process — OS API Execution
Threat actors using it
Tracked threats
23 tracked threats use T1542.
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…critical
- Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)critical
- CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Executioncritical
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…medium
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation…high
- Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)high
- Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…high
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flashhigh
- Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…high
- usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…high
- usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) deviceshigh
- usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…critical
- HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145…high
- P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab…high
- Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS)…high
- PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For…high
- YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…critical
- Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…critical
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited…critical
- Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injectionhigh
- Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader…critical
Detection coverage
Threadlinqs maintains 16 detection rules mapped to T1542 (SPL 6, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1542.001 System Firmware — 8 tracked threats
- T1542.002 Component Firmware — 1 tracked threat
- T1542.003 Bootkit — 7 tracked threats
- T1542.004 ROMMONkit — 0 tracked threats
- T1542.005 TFTP Boot — 2 tracked threats