Sub-technique of T1195 Supply Chain Compromise.View on attack.mitre.org
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.
Rules on DetectionCode tagged with T1195.002.
| Rule | Level | Log source |
|---|---|---|
| Suspicious Child Process of Notepad++ Updater - GUP.Exe | high | windows / process_creation |
| Uncommon File Created by Notepad++ Updater Gup.EXE | high | windows / file_event |
| Notepad++ Updater DNS Query to Uncommon Domains | medium | windows / dns_query |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| 3CX Supply Chain Attack Network Indicators | TTP | NULL | Sysmon EventID 22 |
| GitHub Actions Disable Security Workflow | Anomaly | NULL | GitHub Webhooks |
| Hunting 3CXDesktopApp Software | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Python Network Traffic During Package Build | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3 |
| Python PTH File Creation During Package Installation | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Python PYTHONPATH Modification During Package Installation | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 13 |
| Python Site Hooks Creation During Package Installation | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 11 |
| Shai-Hulud 2 Exfiltration Artifact Files | TTP | NULL | Sysmon for Linux EventID 11, Sysmon EventID 11 |
| Windows Vulnerable 3CX Software | TTP | NULL | Sysmon EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 gained access to production environments where they could inject malicious code into legitimate, signed files and widely distribute them to end users. |
| GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| GroupDragonfly | Dragonfly has placed trojanized installers for control system software on legitimate vendor app stores. |
| GroupFIN7 | FIN7 has gained initial access by compromising a victim's software supply chain. |
| GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR. |
| GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| Used by | Procedure example |
|---|---|
| MalwareCCBkdr | CCBkdr was added to a legitimate, signed version 5.33 of the CCleaner software and distributed on CCleaner's distribution site. |
| MalwareGoldenSpy | GoldenSpy has been packaged with a legitimate tax preparation software. |
| MalwareSUNSPOT | SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus first compromised an “end-of-life" trading software application which was downloaded and executed inside the 3CX enterprise environment. The second compromise modified the Windows and macOS build environments used to distribute the 3CX software to their customer base. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.