Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-672 — Malicious Code Implanted During Chip Programming
CAPEC-672

Malicious Code Implanted During Chip Programming

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. During the programming step of chip manufacture, an adversary with access and necessary technical skills maliciously alters a chip’s intended program logic to produce an effect intended by the adversary when the fully manufactured chip is deployed and in operational use. Intended effects can include the ability of the adversary to remotely control a host system to carry out malicious acts.

Mitigation

Utilize DMEA’s (Defense Microelectronics Activity) Trusted Foundry Program members for acquisition of microelectronic components. | Ensure that each supplier performing hardware development implements comprehensive, security-focused configuration management of microcode and microcode generating tools and software. | Require that provenance of COTS microelectronic components be known whenever procured. | Conduct detailed vendor assessment before acquiring COTS hardware.

Details

Platforms
Supply-chain
Software
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.