The chain, step by step
Each step depends on the one before it. Break any link and the chain stops there.
-
1
Step 1 of 8
The attacker identifies a widely trusted software vendor with a large customer base.
-
2
Step 2 of 8
Access to the vendor's build environment or update server is obtained, often via a phishing email.
-
3
Step 3 of 8
The build process is modified so the injected code runs during normal compilation.
-
4
Step 4 of 8
Code signing is applied automatically, so the resulting artifact carries a valid signature.
-
5
Step 5 of 8
Customers receive the update through the ordinary trusted channel with no warning signs.
-
6
Step 6 of 8
The payload lies dormant, fingerprinting the environment and skipping sandboxes and lab builds.
-
7
Step 7 of 8
A small, high-value subset of installations is selected for hands-on operation.
-
8
Step 8 of 8
Victims are harvested for credentials, source code and access to adjacent customer systems.
Entries behind these steps
The vulnerabilities, techniques and malware that make each stage possible.