Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-533 — Malicious Manual Software Update
CAPEC-533

Malicious Manual Software Update

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An attacker introduces malicious code to the victim's system by altering the payload of a software update, allowing for additional compromise or site disruption at the victim location. These manual, or user-assisted attacks, vary from requiring the user to download and run an executable, to as streamlined as tricking the user to click a URL. Attacks which aim at penetrating a specific network infrastructure often rely upon secondary attack methods to achieve the desired impact. Spamming, for example, is a common method employed as an secondary attack vector. Thus the attacker has in their arsenal a choice of initial attack vectors ranging from traditional SMTP/POP/IMAP spamming and its varieties, to web-application mechanisms which commonly implement both chat and rich HTML messaging within the user interface.

Mitigation

Only accept software updates from an official source.

Details

Platforms
Social-engineering
Supply-chain
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.