# T1542 Pre-OS Boot

> As of 2026-10-05, T1542 (Pre-OS Boot) appears in 23 tracked threats, first reported 2026-03-06 and most recently 2026-09-23, with linked actors including Chaotic Eclipse, INC Ransom, INC Ransom - G1032; it most often appears alongside T1068 (Exploitation for Privilege Escalation).

- **Tracked threats:** 23 (10 critical, 12 high, 1 medium)
- **First seen:** 2026-03-06
- **Last seen:** 2026-09-23
- **Threat actors:** 7
- **Detection rules:** 16 (counts only; Blue tier and above)

## Key facts

- **ID:** T1542
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence, Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1542/

## Activity timeline

T1542 first appeared in tracked threats on 2026-03-06 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 7 reports, and 23 of the 23 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1542 Pre-OS Boot is catalogued by MITRE ATT&CK under the Persistence and Stealth (formerly Defense Evasion) tactics in the Enterprise matrix. Threadlinqs maps 23 of 2623 tracked threats (0.9%) to it; by severity that is 10 critical, 12 high, 1 medium.

Threats that use T1542 most often also use [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (15 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (14 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (14 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (10 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (10 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1542; the most frequent are [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (1), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (1), [Lynx](https://intel.threadlinqs.com/actor/Lynx) (1), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (1).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1542.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1542, per MITRE ATT&CK.

- Command — Command Execution
- Drive — Drive Modification
- Driver — Driver Metadata
- File — File Creation, File Modification
- Firmware — Firmware Modification
- Network Traffic — Network Connection Creation
- Process — OS API Execution

## Threat actors using it

- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 1
- [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse) — 1
- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 1

## Tracked threats

23 tracked threats use T1542.

- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone…](https://intel.threadlinqs.com/threat/TL-2026-1912) — critical — 2026-08-06
- [Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)](https://intel.threadlinqs.com/threat/TL-2026-1840) — critical — 2026-08-03
- [CVE-2026-65094: Write-What-Where Vulnerability in NVIDIA BlueField-3 VIRTIO-Net Enables Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1812) — critical — 2026-08-01
- [UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…](https://intel.threadlinqs.com/threat/TL-2026-1726) — medium — 2026-07-27
- [Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-1330) — high — 2026-07-14
- [Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)](https://intel.threadlinqs.com/threat/TL-2026-1298) — high — 2026-07-14
- [Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related…](https://intel.threadlinqs.com/threat/TL-2026-1251) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — high — 2026-07-11
- [Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1105) — high — 2026-07-05
- [usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB…](https://intel.threadlinqs.com/threat/TL-2026-0876) — high — 2026-06-19
- [usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices](https://intel.threadlinqs.com/threat/TL-2026-0871) — high — 2026-06-19
- [usbliter8 — Unpatchable BootROM USB DMA Exploit on Apple A12/A12X/A12Z/A13 and S4/S5 Chips Bypassing Secure…](https://intel.threadlinqs.com/threat/TL-2026-0860) — critical — 2026-06-18
- [HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145…](https://intel.threadlinqs.com/threat/TL-2026-0798) — high — 2026-06-15
- [P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab…](https://intel.threadlinqs.com/threat/TL-2026-0752) — high — 2026-06-10
- [Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS)…](https://intel.threadlinqs.com/threat/TL-2026-0732) — high — 2026-06-09
- [PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For…](https://intel.threadlinqs.com/threat/TL-2026-0543) — high — 2026-05-21
- [YellowKey & GreenPlasma — Unpatched Windows BitLocker Bypass & CTFMON LPE Zero-Days With Public PoC…](https://intel.threadlinqs.com/threat/TL-2026-0512) — critical — 2026-05-13
- [Firestarter Malware Persists on Cisco ASA/Firepower Through Firmware Updates (CVE-2025-20333…](https://intel.threadlinqs.com/threat/TL-2026-0422) — critical — 2026-04-24
- [Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0391) — critical — 2026-04-19
- [Keenadu: Firmware-Level Android Supply Chain Backdoor via Zygote Process Injection](https://intel.threadlinqs.com/threat/TL-2026-0251) — high — 2026-03-19
- [Android Exploit Chain — Saito Tech Commercial Spyware: ART Runtime RCE, Binder UAF LPE, Pixel Bootloader…](https://intel.threadlinqs.com/threat/TL-2026-0177) — critical — 2026-03-06

## Related CVEs

CVEs referenced by the tracked threats that use T1542, most frequent first.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20200](https://intel.threadlinqs.com/cve/CVE-2026-20200)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-20945](https://intel.threadlinqs.com/cve/CVE-2026-20945)
- [CVE-2026-22104](https://intel.threadlinqs.com/cve/CVE-2026-22104)
- [CVE-2026-22107](https://intel.threadlinqs.com/cve/CVE-2026-22107)
- [CVE-2026-22112](https://intel.threadlinqs.com/cve/CVE-2026-22112)
- [CVE-2026-23666](https://intel.threadlinqs.com/cve/CVE-2026-23666)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-26151](https://intel.threadlinqs.com/cve/CVE-2026-26151)
- [CVE-2026-27913](https://intel.threadlinqs.com/cve/CVE-2026-27913)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-32157](https://intel.threadlinqs.com/cve/CVE-2026-32157)

## Detection coverage

Threadlinqs maintains 16 detection rules mapped to T1542 (SPL 6, KQL 5, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

16 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1542.001 System Firmware — 8 tracked threats
- T1542.002 Component Firmware — 1 tracked threat
- T1542.003 Bootkit — 7 tracked threats
- T1542.004 ROMMONkit — 0 tracked threats
- T1542.005 TFTP Boot — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1542
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
