Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1195.002 Compromise Software Supply Chain |
GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
| T1195.002 Compromise Software Supply Chain |
GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| T1195.002 Compromise Software Supply Chain |
GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| T1195.002 Compromise Software Supply Chain |
GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| T1195.002 Compromise Software Supply Chain |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR. |
| T1195.002 Compromise Software Supply Chain |
GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| T1195.002 Compromise Software Supply Chain |
GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1195.002 Compromise Software Supply Chain |
GroupThreat Group-3390 | Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.