SYNful Knock is a Cisco router firmware implant and backdoor that targets Cisco IOS-based network infrastructure by replacing or modifying the device operating system image. Publicly identified in 2015, it is designed to provide covert, persistent access on compromised routers and to survive device reboots. The implant enables operators to load additional modules and maintain a hidden foothold on affected devices, making it suitable for long-term espionage and network-infrastructure compromise.
The malware has been associated with Russian state-linked activity, including reporting that ties its use to FSB Center 16-related clusters tracked as Berserk Bear, Dragonfly, Energetic Bear, and Static Tundra. It has been referenced as part of campaigns against legacy or unpatched Cisco devices, especially where attackers first gained access through weaknesses such as exposed or weak SNMP configurations or exploitation of Cisco Smart Install vulnerability CVE-2018-0171. In those operations, SYNful Knock served as a durable persistence mechanism after initial compromise.
Operationally, SYNful Knock functions as a stealthy firmware-level backdoor on network devices. It allows continued remote access outside normal endpoint visibility and has been described as triggerable through specially crafted network traffic. Its placement on routers makes it strategically valuable for maintaining long-term access, supporting post-compromise control of network infrastructure, and enabling broader espionage objectives against sectors including critical infrastructure, telecommunications, higher education, manufacturing, energy, and other enterprise environments that rely on Cisco networking equipment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The alert directly connects them to reports of the Russian Federal Security Service's (FSB) Center 16 - aka Berserk Bear - accused of using a flaw (CVE-2018-0171) Cisco patched in 2018... The Cisco issue is with the Smart Install feature of Cisco IOS and IOS XE software, a CVSS 9.8 flaw, and one that many end-of-life-kit can't patch.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This unit has also deployed custom tools to certain Cisco devices, such as the malware publicly identified as "SYNful Knock" in 2015.
Кастомный инструментарий - в 2015 году публично идентифицировано вредоносное ПО SYNful Knock, которое подразделение разворачивало на определённых устройствах Cisco ... SYNful Knock, публично идентифицированный в 2015 году, - конкретный пример: модифицированный IOS-образ исполняет имплант при каждой загрузке.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
The FBI detected Russian FSB cyber actors exploiting Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to broadly target entities in the United States and globally.
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
Remote access to the device can then be achieved by sending a specifically crafted TCP SYN packet, commonly referred to as a “magic packet.”
Persistent access is maintained with reused SNMP credentials or, when required, the SYNful Knock malware, which survives reboots.
Static Tundra has been observed leveraging a Cisco IOS firmware implant known as SYNful Knock to achieve persistent access to compromised systems. SYNful Knock is a modular implant that attackers inject into a Cisco IOS image and then load onto the compromised device.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Имплант для сетевых устройств Cisco, связанный с модификацией образа IOS для обеспечения скрытого и устойчивого несанкционированного доступа при каждой загрузке устройства.
A malware implant/backdoor used to maintain persistent access on compromised Cisco network devices, including surviving device reboots.
Custom malware/backdoor deployed to certain Cisco devices by the FSB Center 16 unit to compromise networking infrastructure.
Backdoor used to maintain persistent, covert access to compromised Cisco networking devices, providing a hidden foothold that can survive reboots.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.