Attack chain 8 steps

Supply Chain Compromise

The whole chain in order — from the first touch to the objective — with the point at which each stage could have been stopped.

The chain, step by step

Each step depends on the one before it. Break any link and the chain stops there.

  1. 1

    Step 1 of 8

    The attacker identifies a widely trusted software vendor with a large customer base.

  2. 2

    Step 2 of 8

    Access to the vendor's build environment or update server is obtained, often via a phishing email.

  3. 3

    Step 3 of 8

    The build process is modified so the injected code runs during normal compilation.

  4. 4

    Step 4 of 8

    Code signing is applied automatically, so the resulting artifact carries a valid signature.

  5. 5

    Step 5 of 8

    Customers receive the update through the ordinary trusted channel with no warning signs.

  6. 6

    Step 6 of 8

    The payload lies dormant, fingerprinting the environment and skipping sandboxes and lab builds.

  7. 7

    Step 7 of 8

    A small, high-value subset of installations is selected for hands-on operation.

  8. 8

    Step 8 of 8

    Victims are harvested for credentials, source code and access to adjacent customer systems.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used