Supply chain attacks: threats targeting service providers and design offices
ID: 87cd19fc-b7db-4a25-ac3a-447b4461b0f0
STIX ID: report--87cd19fc-b7db-4a25-ac3a-447b4461b0f0
Threat Score
75/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI (v1.0, Oct 2019) warns of supply-chain attacks targeting service providers and design offices: an initial wave using PlugX and a more recent wave relying on stolen credentials and legitimate administration tools to access client networks. The report documents attacker TTPs (VPN/TOR anonymization, RDP lateral movement, ProcDump/CertMig/Mimikatz usage, browser-monitoring custom malware), IOCs (VPN exit-node IP ranges, VMware MAC prefixes, registry PortProxy keys, unusual folders), detection rules and pragmatic recommendations for service providers and clients to monitor, segment and harden connections.
