Attackers may maintain root persistence despite a factory reset
Assessment
CISA's advisory says an actor "may be able to" persist through factory reset, citing unpublished lab research. The only published forensic case points the other way: Mandiant found UNC5325's LITTLELAMB.WOOLTEA modified the factory-reset partition, but the partition's kernel uses a different encryption key from the running version, so on any appliance updated at least once the modification fails, and a reset appliance examined by Mandiant and Ivanti showed no persistence. Persistence on a never-updated appliance is untested in public.
Where this claim appeared
CISA · 2024-02-29
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060bWhat “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
Ivanti Connect Secure zero-days: one December intrusion, 2,100 backdoored appliances and a federal disconnect orderThink this assessment is wrong? Report an error.