Attacker code arrives via a trusted update
A supplier's build or update mechanism is compromised, so a routine update to widely-installed software carries attacker code. Because it comes through a trusted channel, it is installed with the confidence normally given to that vendor.
Get executed inside the environment through legitimate, trusted software distribution.
- Vendor security assessment and update provenance verification
- Staged rollout and monitoring of updates before wide deployment
- Application allow-listing that still constrains trusted software's behaviour
- Trusted software making unexpected network connections
- New behaviour from an application right after an update
- Update-delivered binaries with anomalous characteristics
- Review update provenance and staged-rollout controls
- Assess vendor-risk and third-party software governance
- Test whether trusted-software behaviour is still monitored
Attacker capability is now running inside the environment under a trusted name.