Supply Chain Compromise

T1195

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Supply chain compromise can take place at any stage of the supply chain including:

* Manipulation of development tools
* Manipulation of a development environment
* Manipulation of source code repositories (public or private)
* Manipulation of source code in open-source dependencies
* Manipulation of software update/distribution mechanisms
* Compromised/infected system images (removable media infected at the factory)
* Replacement of legitimate software with modified versions
* Sales of modified/counterfeit products to legitimate distributors
* Shipment interdiction

While supply chain compromise can impact any component of hardware or software, adversaries looking to gain execution have often focused on malicious additions to legitimate software in software distribution or update channels. Adversaries may limit targeting to a desired victim set or distribute malicious software to a broad set of consumers but only follow up with specific victims. Popular open-source projects that are used as dependencies in many applications may also be targeted as a means to add malicious code to users of the dependency.

In some cases, adversaries may conduct “second-order” supply chain compromises by leveraging the access gained from an initial supply chain compromise to further compromise a software component. This may allow the threat actor to spread to even more victims.

Detection rules36

Rules on DetectionCode tagged with T1195 or one of its sub-techniques.

Sigma5

Splunk31

RuleTypeRiskData sourceTechnique
3CX Supply Chain Attack Network IndicatorsTTPNULLSysmon EventID 22T1195.002
GitHub Actions Disable Security WorkflowAnomalyNULLGitHub WebhooksT1195.002
GitHub Dependabot AlertAnomalyNULLGitHub WebhooksT1195.001
GitHub Enterprise Delete Branch RulesetAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Disable 2FA RequirementAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Disable Audit Log Event StreamAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Disable Classic Branch Protection RuleAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Disable DependabotAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Disable IP Allow ListAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Modify Audit Log Event StreamAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Pause Audit Log Event StreamAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Register Self Hosted RunnerAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Remove OrganizationAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Repository ArchivedAnomalyNULLGitHub Enterprise Audit LogsT1195
GitHub Enterprise Repository DeletedAnomalyNULLGitHub Enterprise Audit LogsT1195

Sub-techniques3

IDNameExamples
T1195.001Compromise Software Dependencies and Development Tools9
T1195.002Compromise Software Supply Chain14
T1195.003Compromise Hardware Supply Chain0

Groups3

Software2

Campaigns0

None recorded.

Procedure examples5

Groups3

Used byProcedure example
GroupEmber Bear

Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations.

GroupOilRig

OilRig has leveraged compromised organizations to conduct supply chain attacks on government entities.

GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments.

Software2

Used byProcedure example
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

MalwareRaccoon Stealer

Raccoon Stealer has been distributed through cracked software downloads.

References8

  1. Avast CCleaner3 2018 Open source
    Avast Threat Intelligence Team. (2018, March 8). New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities. Retrieved March 15, 2018.
  2. Command Five SK 2011 Open source
    Command Five Pty Ltd. (2011, September). SK Hack by an Advanced Persistent Threat. Retrieved November 17, 2024.
  3. IBM Storwize Open source
    IBM Support. (2017, April 26). Storwize USB Initialization Tool may contain malicious code. Retrieved May 28, 2019.
  4. Krebs 3cx overview 2023 Open source
    Brian Krebs. (2023, April 20). 3CX Breach Was a Double Supply Chain Compromise. Retrieved May 22, 2025.
  5. Microsoft Dofoil 2018 Open source
    Windows Defender Research. (2018, March 7). Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign. Retrieved March 20, 2018.
  6. Schneider Electric USB Malware Open source
    Schneider Electric. (2018, August 24). Security Notification – USB Removable Media Provided With Conext Combox and Conext Battery Monitor. Retrieved May 28, 2019.
  7. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  8. Trendmicro NPM Compromise Open source
    Trendmicro. (2018, November 29). Hacker Infects Node.js Package to Steal from Bitcoin Wallets. Retrieved April 10, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.