ThreatPaper
Assessed, Not Confirmed

Attackers may maintain root persistence despite a factory reset

Assessment

CISA's advisory says an actor "may be able to" persist through factory reset, citing unpublished lab research. The only published forensic case points the other way: Mandiant found UNC5325's LITTLELAMB.WOOLTEA modified the factory-reset partition, but the partition's kernel uses a different encryption key from the running version, so on any appliance updated at least once the modification fails, and a reset appliance examined by Mandiant and Ivanti showed no persistence. Persistence on a never-updated appliance is untested in public.

Where this claim appeared

CISA · 2024-02-29

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Ivanti Connect Secure zero-days: one December intrusion, 2,100 backdoored appliances and a federal disconnect order

Think this assessment is wrong? Report an error.