Skip to content
BreachPathAttack Path LibraryStart
AdvancedRansomware

Supplier software update to ransomware

A trusted software update from a compromised supplier delivers attacker code into the environment, which is used to establish control and deploy ransomware from the inside.

Technologies
SaaS (generic), On-premises Active Directory
Entry points
Supplier compromise
Sectors
Manufacturing, Healthcare, Retail
Stages
3
01

Attacker code arrives via a trusted update

A supplier's build or update mechanism is compromised, so a routine update to widely-installed software carries attacker code. Because it comes through a trusted channel, it is installed with the confidence normally given to that vendor.

Attacker objective

Get executed inside the environment through legitimate, trusted software distribution.

Controls that should stop this
  • Vendor security assessment and update provenance verification
  • Staged rollout and monitoring of updates before wide deployment
  • Application allow-listing that still constrains trusted software's behaviour
What defenders should see
  • Trusted software making unexpected network connections
  • New behaviour from an application right after an update
  • Update-delivered binaries with anomalous characteristics
What a pentest validates
  • Review update provenance and staged-rollout controls
  • Assess vendor-risk and third-party software governance
  • Test whether trusted-software behaviour is still monitored
Business impact

Attacker capability is now running inside the environment under a trusted name.

02

Control is established and expanded

The delivered code beacons out, and the attacker uses it to establish persistence, harvest credentials and expand across the environment toward the privilege needed for broad impact.

Attacker objective

Turn the delivered foothold into durable, privileged internal access.

Controls that should stop this
  • Egress monitoring and control to catch command-and-control traffic
  • Least privilege and credential-theft protections
  • Segmentation limiting spread from any single host
What defenders should see
  • Beaconing / command-and-control network patterns
  • Credential-access alerts and lateral movement
  • Persistence mechanisms established after an update
What a pentest validates
  • Assumed-breach test from a supplier-delivered foothold
  • Validate egress monitoring and C2 detection
  • Test segmentation and credential protections
Business impact

The attacker holds durable, expanding control inside the estate.

03

Ransomware is deployed from the inside

With sufficient reach, the attacker disrupts backups and deploys encryption across the environment, often exfiltrating data first for double extortion.

Attacker objective

Impair recovery and encrypt widely from a trusted internal position.

Controls that should stop this
  • Immutable, offline, access-segregated backups tested for restore
  • Mass-file-change and shadow-copy-deletion alerting
  • Application control limiting unauthorised execution
What defenders should see
  • Backup tampering and recovery-inhibition events
  • Mass encryption behaviour across hosts
  • Large data egress preceding encryption
What a pentest validates
  • Confirm backups survive a privileged internal compromise
  • Test detection of recovery inhibition and mass encryption
  • Validate segmentation limits blast radius from a supplier foothold
Business impact

The estate is encrypted from within via trusted software — severe outage and extortion pressure.

ATT&CK techniques in this chain

If this chain completes

A software-supply-chain compromise bypasses the perimeter entirely by arriving as trusted, signed-looking software — landing attacker capability deep inside many organisations at once.

Should you test this against your environment?

Turn this chain into a scoped red-team brief — objective, systems and identities in scope, testing assumptions and the questions to answer before commissioning.