Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-537 — Infiltration of Hardware Development Environment
CAPEC-537

Infiltration of Hardware Development Environment

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An adversary, leveraging the ability to manipulate components of primary support systems and tools within the development and production environments, inserts malicious software within the hardware and/or firmware development environment. The infiltration purpose is to alter developed hardware components in a system destined for deployment at the victim's organization, for the purpose of disruption or further compromise.

Mitigation

Verify software downloads and updates to ensure they have not been modified be adversaries | Leverage antivirus tools to detect known malware | Do not download software from untrusted sources | Educate designers, developers, engineers, etc. on social engineering attacks to avoid downloading malicious software via attacks such as phishing attacks

Details

Platforms
Supply-chain
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.