Umbra Wiki technique technique/T1195.002
Back to wiki

T1195.002 — Compromise Software Supply Chain

provenance: imported · ATT&CK: T1195.002

T1195.002: Compromise Software Supply Chain

MITRE ATT&CK® Enterprise technique

Tactics Initial Access
Platforms Linux, Windows, macOS
Permissions required
Version 1.1
Parent technique T1195

Description

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.(Citation: Avast CCleaner3 2018)(Citation: Command Five SK 2011)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1195/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/