logo

Supply chain attacks: threats targeting service providers and design offices

ID: 87cd19fc-b7db-4a25-ac3a-447b4461b0f0

STIX ID: report--87cd19fc-b7db-4a25-ac3a-447b4461b0f0

Threat Score

75/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI (v1.0, Oct 2019) warns of supply-chain attacks targeting service providers and design offices: an initial wave using PlugX and a more recent wave relying on stolen credentials and legitimate administration tools to access client networks. The report documents attacker TTPs (VPN/TOR anonymization, RDP lateral movement, ProcDump/CertMig/Mimikatz usage, browser-monitoring custom malware), IOCs (VPN exit-node IP ranges, VMware MAC prefixes, registry PortProxy keys, unusual folders), detection rules and pragmatic recommendations for service providers and clients to monitor, segment and harden connections.