Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.(Citation: Avast CCleaner3 2018)(Citation: Command Five SK 2011)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
is blocked by Update Software
is blocked by Vulnerability Scanning
is blocked by Provenance
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Least Functionality
is blocked by User-Installed Software
is blocked by Assessments
is blocked by Product Tampering and Counterfeiting (PTC)
is blocked by Unsupported Technology Assets, Applications and/or Services (TAAS)
is blocked by Acquisition Strategies, Tools & Methods
is blocked by Threat Hunting
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum German English