Compromise Software Supply Chain

T1195.002

Sub-technique of T1195 Supply Chain Compromise.View on attack.mitre.org

About this technique

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.

Detection rules12

Rules on DetectionCode tagged with T1195.002.

Sigma3

RuleLevelLog source
Suspicious Child Process of Notepad++ Updater - GUP.Exehighwindows / process_creation
Uncommon File Created by Notepad++ Updater Gup.EXEhighwindows / file_event
Notepad++ Updater DNS Query to Uncommon Domainsmediumwindows / dns_query

Splunk9

RuleTypeRiskData source
3CX Supply Chain Attack Network IndicatorsTTPNULLSysmon EventID 22
GitHub Actions Disable Security WorkflowAnomalyNULLGitHub Webhooks
Hunting 3CXDesktopApp SoftwareHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Python Network Traffic During Package BuildAnomalyNULLSysmon EventID 1 AND Sysmon EventID 3
Python PTH File Creation During Package InstallationAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11
Python PYTHONPATH Modification During Package InstallationTTPNULLSysmon EventID 1 AND Sysmon EventID 13
Python Site Hooks Creation During Package InstallationTTPNULLSysmon EventID 1 AND Sysmon EventID 11
Shai-Hulud 2 Exfiltration Artifact FilesTTPNULLSysmon for Linux EventID 11, Sysmon EventID 11
Windows Vulnerable 3CX SoftwareTTPNULLSysmon EventID 1

Groups9

Software3

Campaigns2

Procedure examples14

Groups9

Used byProcedure example
GroupAPT41

APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users.

GroupCobalt Group

Cobalt Group has compromised legitimate web browser updates to deliver a backdoor.

GroupDaggerfly

Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims.

GroupDragonfly

Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores.

GroupFIN7

FIN7 has gained initial access by compromising a victim's software supply chain.

GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

GroupMoonstone Sleet

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

View all 9 groups examples

Software3

Used byProcedure example
MalwareCCBkdr

CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site.

MalwareGoldenSpy

GoldenSpy has been packaged with a legitimate tax preparation software.

MalwareSUNSPOT

SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product.

Campaigns2

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

References2

  1. Avast CCleaner3 2018 Open source
    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.
  2. Command Five SK 2011 Open source
    Command Five Pty Ltd. (2011, September). SK Hack by an Advanced Persistent Threat. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.