LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1474.003: Compromise Software Supply Chain

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

MobileT1474.003Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

This mobile technique matters because a device can be compromised before the enterprise ever installs or receives the app: source code, compiled releases, or update and distribution mechanisms may be altered upstream. For leaders, the risk is less about a single user mistake and more about trust in mobile software procurement, update channels, and device eligibility for enterprise access.

Executive priority

Prioritize this where Android or iOS devices access sensitive enterprise data, regulated workflows, or operational systems. Ask whether the organization can prove which mobile apps and device builds are trusted, current, and eligible for access. Budget and governance decisions should focus on mobile supply-chain assurance, security update commitments, unsupported-device retirement, and auditable access controls tied to device update state.

Technical view

ATT&CK provides no official detection text and no tactic mapping for this sub-technique, but it is scoped to Android and iOS and is a sub-technique of Supply Chain Compromise. SOC, detection, and IR teams should validate whether they can investigate app provenance, signing identity, version drift, update source, device patch level, and Android system partition integrity. Relationship context shows DET0721 as a related detection strategy, but its details are not supplied here. ATT&CK also maps several mobile software entries to this behavior, including Adups, Allwinner, Stealth Mango, Triada, and CHEMISTGAMES, supporting the need to treat mobile supply-chain trust as an investigative and control domain rather than only an endpoint alerting problem.

Likely telemetry

  • Mobile device inventory for Android and iOS assets
  • Mobile app inventory, app version, package/bundle identifier, installation source, and update history
  • Application signing certificate, hash, and release metadata where available
  • MDM/UEM compliance state and enterprise resource access decisions
  • Device operating system version and security patch level

Detection direction

  • Confirm whether DET0721 or equivalent internal analytics exist, because the supplied ATT&CK object does not provide detection logic.
  • Baseline approved mobile applications, expected signing certificates, authorized distribution channels, and known-good versions; alert on deviations that are meaningful in the local environment.
  • Correlate suspicious app provenance or version changes with device compliance, patch level, and access to enterprise resources.
  • Treat unsupported, unpatched, or unverifiable devices as higher-risk investigation targets, especially when they run sensitive mobile applications.
  • Tune carefully for legitimate app updates, regional distribution differences, enterprise re-signing, beta channels, and managed app deployments to avoid excessive false positives.

Mitigation priorities

  • Require vendor, carrier, and device procurement commitments for prompt security updates over a defined support period.
  • Install security updates in response to discovered vulnerabilities and enforce recent security patch levels for enterprise access.
  • Decommission devices that no longer receive security updates.
  • Limit or block access to enterprise resources from devices that have not installed recent security updates, consistent with the M1001 mitigation relationship.
  • For Android, ensure devices include and enable Verified Boot to cryptographically protect system partition integrity, consistent with M1004.
Additional notes and limits

The most important defensive question is whether the organization can validate trust after software has passed through external development, build, and distribution paths. This object is especially relevant to mobile security architecture, MDM/UEM policy, incident response evidence collection, and compliance demonstrations around device eligibility and software provenance.

Official ATT&CK detection guidance and tactics are not provided for this object. The supplied relationship to DET0721 names a detection strategy but does not include its analytic details. Mitigation text is limited to security updates and Android system partition integrity. Local telemetry, mobile management capabilities, procurement records, and app distribution practices are required to determine actual exposure and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Compromise Software Supply Chain

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
MobileT1474Supply Chain CompromiseThis object subtechnique of Supply Chain Compromise.
Associated objects

Groups, software, and campaigns

MalwareMobile

S0309: Adups

Adups is software that was pre-installed onto Android devices, including those made by BLU Products. The software was reportedly designed to help a Chinese phone manufacturer monitor user behavior, transferring sensitive data to a Chinese server. [1] [2]

MalwareMobile

S0424: Triada

Triada was first reported in 2016 as a second stage malware. Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.[1]

Android
MalwareMobile

S0328: Stealth Mango

Stealth Mango is Android malware that has reportedly been used to successfully compromise the mobile devices of government officials, members of the military, medical professionals, and civilians. The iOS malware known as Tangelo is believed to be from the same developer. [1]

Android
MalwareMobile

S0319: Allwinner

Allwinner is a company that supplies processors used in Android tablets and other devices. A Linux kernel distributed by Allwinner for use on these devices reportedly contained a backdoor. [1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
988454b897f00424...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle988454b897f0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NYTimes-BackDoor

    Matt Apuzzo and Michael S. Schmidt. (2016, November 15). Secret Back Door in Some U.S. Phones Sent Data to China, Analysts Say. Retrieved February 6, 2017.

    Open source URL
  2. [2]
    BankInfoSecurity-BackDoor

    Jeremy Kirk. (2016, November 16). Why Did Chinese Spyware Linger in U.S. Phones?. Retrieved February 6, 2017.

  3. [3]
    Google Triada June 2019

    Lukasz Siewierski. (2019, June 6). PHA Family Highlights: Triada. Retrieved July 16, 2019.

    Open source URL
  4. [4]
    Krebs-Triada June 2019

    Krebs, B. (2019, June 25). Tracing the Supply Chain Attack on Android. Retrieved July 16, 2019.

    Open source URL
  5. [5]
    Lookout-StealthMango

    Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.

    Open source URL
  6. [6]
    HackerNews-Allwinner

    Mohit Kumar. (2016, May 11). Kernel Backdoor found in Gadgets Powered by Popular Chinese ARM Maker. Retrieved September 18, 2018.

    Open source URL
  7. [7]
    CYBERWARCON CHEMISTGAMES

    B. Leonard, N. Mehta. (2019, November 21). The Secret Life of Sandworms. Retrieved December 31, 2020.

    Open source URL
  8. [8]
    NIST Mobile Threat CatalogueSPC-11
    Open source URL
  9. [9]
    NIST Mobile Threat CatalogueSPC-11
    Open source URL
  10. [10]
    NIST Mobile Threat CatalogueSPC-12
    Open source URL
  11. [11]
    NIST Mobile Threat CatalogueSPC-12
    Open source URL
  12. [12]
    NIST Mobile Threat CatalogueSPC-18
    Open source URL
  13. [13]
    NIST Mobile Threat CatalogueSPC-18
    Open source URL
  14. [14]
    NIST Mobile Threat CatalogueSPC-20
    Open source URL
  15. [15]
    NIST Mobile Threat CatalogueSPC-20
    Open source URL
  16. [16]
    NIST Mobile Threat CatalogueSPC-4
    Open source URL
  17. [17]
    NIST Mobile Threat CatalogueSPC-4
    Open source URL
  18. [18]
    mitre-attackT1474.003
    Open source URL
  19. [19]
    mitre-attackT1474.003
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.