Detailedlikelihood: Lowseverity: HighDraft
CAPEC-670Software Development Tools Maliciously Altered
Abstraction
Detailed
Status
Draft
Likelihood
Low
Severity
High
Description
An adversary with the ability to alter tools used in a development environment causes software to be developed with maliciously modified tools. Such tools include requirements management and database tools, software design tools, configuration management tools, compilers, system build tools, and software performance testing and load testing tools. The adversary then carries out malicious acts once the software is deployed including malware infection of other systems to support further compromises.
MITRE ATT&CK crosswalk· 2
Related attack patterns· 2
Related to2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Trusted Developer Utilities Proxy Executiont1127 | 100% | live |
| SubTechnique | Compromise Software Dependencies and Development Toolst1195.001 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.