I don’t have particular experience with firmware hacking but how would you achieve persistence with just a simple malloc/bad malloc replacement? What if user decides to reflash the ROM during runtime? I imagine persistence would require emulating the entire firmware update process.
In order to emulate the firmware update process, you would need to reverse engineer a large portion of the binary, right? This is where LLMs would be helpful.