Supply Chain Compromise
Description
Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows. Supply chain compromise is the manipulation of products, such as devices or software, or their delivery mechanisms before receipt by the end consumer. Adversary compromise of these products and mechanisms is done for the goal of data or system compromise, once infected products are introduced to the target environment. Supply chain compromise can occur at all stages of the supply chain, from manipulation of development tools and environments to manipulation of developed products and tools distribution mechanisms. This may involve the compromise and replacement of legitimate software and patches, such as on third party or vendor websites. Targeting of supply chain compromise can be done in attempts to infiltrate the environments of a specific audience. In control systems environments with assets in both the IT and OT networks, it is possible a supply chain compromise affecting the IT environment could enable further access to the OT environment. Counterfeit devices may be introduced to the global supply chain posing safety and cyber risks to asset owners and operators. These devices may not meet the safety, engineering and manufacturing requirements of regulatory bodies but may feature tagging indicating conformance with industry standards. Due to the lack of adherence to standards and overall lesser quality, the counterfeit products may pose a serious safety and operational risk. (Citation: Control Global May 2019) Yokogawa identified instances in which their customers received counterfeit differential pressure transmitters using the Yokogawa logo. The counterfeit transmitters were nearly indistinguishable with a semblance of functionality and interface that mimics the genuine product. (Citation: Control Global May 2019) F-Secure Labs analyzed the approach the adversary used to compromise victim systems with Havex. (Citation: Daavid Hentunen, Antti Tikkanen June 2014) The adversary planted trojanized software installers available on legitimate ICS/SCADA vendor websites. After being downloaded, this software infected the host computer with a Remote Access Trojan (RAT).
Mapped SPARTA techniques
9 techniques
T0862 'Supply Chain Compromise' is the ATT&CK ICS initial-access technique for compromising target products via their supply chain; SPARTA IA-0001 'Compromise Supply Chain' is the parent-level spacecraft equivalent. Tactic and activity align directly.
Software dependencies and development tools compromise is a software-supply-chain pattern; T0862 'Supply Chain Compromise' covers this at parent level (ICS has no specific .001-style sub-technique for dependencies/dev-tools).
Software supply chain compromise (insertion of malicious code into legitimate FSW prior to distribution) maps directly to T0862 'Supply Chain Compromise' — ICS treats the supply-chain compromise pattern at parent level without sub-technique granularity.
Hardware supply chain compromise (insertion of vulnerabilities/backdoors into hardware components) maps directly to T0862 'Supply Chain Compromise' at the parent level applied to hardware components.
SDR compromise often proceeds via the firmware/software supply chain (vendor build pipeline, FSW update repository); T0862 'Supply Chain Compromise' covers this delivery path complementary to T0860's primary wireless-compromise framing.
On-orbit update (FSW patch, configuration push, firmware uplink) is the spacecraft's software supply chain in operation; T0862 'Supply Chain Compromise' covers compromise of this update channel as initial-access vector. Tactic and activity align.
Vendor compromise also frequently feeds into supply-chain compromise (vendor delivers backdoored components/updates); T0862 'Supply Chain Compromise' covers this delivery-path aspect of vendor abuse, complementary to T0822's remote-service framing.
Assembly, Test, and Launch Operations (ATLO) is the integration phase of the spacecraft's supply chain; compromise during ATLO is supply-chain compromise applied to the integration stage — exact match for T0862 at parent level. Tactic and activity align.
Hardware backdoors are typically introduced via the hardware supply chain; T0862 'Supply Chain Compromise' is the canonical introduction path. Cross-tactic moderate (T0862 in initial-access vs SPARTA PER-0002.01 persistence) because the hardware backdoor's effect is persistent access even though MITRE ICS classifies the supply-chain compromise itself as initial-access.
Cite as SafeMode Space, mitre-attack-ics T0862.