SYNful Knock is a Cisco router firmware implant and backdoor that targets Cisco IOS-based network infrastructure devices. Publicly identified in 2015, it consists of a modified Cisco IOS image that executes an implant at boot and provides persistent, covert access that survives device reboots. The implant enables operators to maintain a hidden foothold on compromised routers and to extend functionality by loading additional modules.
SYNful Knock has been associated with long-term espionage activity against enterprise and critical infrastructure network devices. Reporting has linked its use to Russian state-sponsored activity clusters including Static Tundra and related FSB Center 16-associated operations also tracked as Berserk Bear, Dragonfly, and Energetic Bear. It has been used on selected Cisco devices as part of broader campaigns focused on durable access to network infrastructure, traffic visibility, credential and configuration theft, and follow-on intrusion activity.
The malware’s defining characteristic is firmware-level persistence through a patched system image rather than ordinary configuration-only abuse. This allows the implant to remain active across reboots and makes it particularly valuable for stealthy, long-duration access on routers that often lack conventional endpoint monitoring. In operational use, SYNful Knock has been described as permitting covert remote access and module loading, and as supporting continued access to compromised devices while threat actors conduct reconnaissance, collect device configurations, and facilitate further operations inside victim environments.
Observed victimology and campaign context indicate targeting of Cisco network devices in sectors such as telecommunications, higher education, manufacturing, and critical infrastructure, with activity reported globally and heightened operational relevance in espionage campaigns affecting Ukraine and allied countries. SYNful Knock is best understood as a specialized network-device implant used to preserve clandestine control over compromised Cisco infrastructure for intelligence collection and post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Два вектора - SNMP и семилетняя CVE-2018-0171 в Cisco Smart Install... Уязвимость затрагивает Cisco IOS и IOS XE: некорректная валидация пакетов позволяет неаутентифицированному удалённому атакующему вызвать перезагрузку устройства (DoS) или выполнить произвольный код... Статус KEV: включена в каталог CISA Known Exploited Vulnerabilities с 3 ноября 2021 года - подтверждение активной эксплуатации.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Кастомный инструментарий - в 2015 году публично идентифицировано вредоносное ПО SYNful Knock, которое подразделение разворачивало на определённых устройствах Cisco ... SYNful Knock, публично идентифицированный в 2015 году, - конкретный пример: модифицированный IOS-образ исполняет имплант при каждой загрузке.
Кастомный инструментарий - в 2015 году публично идентифицировано вредоносное ПО SYNful Knock, которое подразделение разворачивало на определённых устройствах Cisco ... SYNful Knock, публично идентифицированный в 2015 году, - конкретный пример: модифицированный IOS-образ исполняет имплант при каждой загрузке.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
The FBI detected Russian FSB cyber actors exploiting Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to broadly target entities in the United States and globally.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
Remote access to the device can then be achieved by sending a specifically crafted TCP SYN packet, commonly referred to as a “magic packet.”
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
Static Tundra has been observed leveraging a Cisco IOS firmware implant known as SYNful Knock to achieve persistent access to compromised systems. SYNful Knock is a modular implant that attackers inject into a Cisco IOS image and then load onto the compromised device.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Имплант для сетевых устройств Cisco, связанный с модификацией образа IOS для обеспечения скрытого и устойчивого несанкционированного доступа при каждой загрузке устройства.
A malware implant/backdoor used to maintain persistent access on compromised Cisco network devices, including surviving device reboots.
Backdoor used to maintain persistent, covert access to compromised Cisco networking devices, providing a hidden foothold that can survive reboots.
SYNful Knock is a custom backdoor implant for Cisco routers that modifies device firmware to provide persistent access, allowing attackers to return at will, steal configuration files, and use the router as a launch point for further attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.