Compliance Node Overview
MITRE ATT&CK T0873 (Project File Infection) is an ATT&CK for ICS Persistence technique. Adversaries may attempt to infect project files with malicious code. These project files may consist of objects, program organization units, variables such as tags, documentation, and other configurations needed for PLC programs to function. Using built in functions of the engineering software, adversaries may be able to download an infected program to a PLC in the operating environment enabling further Execution and Persistence techniques. Affected asset classes: None. MITRE-documented mitigations include M0922 Restrict File and Directory Permissions, M0941 Encrypt Sensitive Information, M0947 Audit, M0945 Code Signing. Operational-technology controls map to NIST SP 800-82 Rev 3 and the IEC/ISA 62443 series.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0873/
SHA-256 integrity: d6f6f53908157f46a8e6f32e0ead7ddabbbe7fc87d8608cb23aa03d7fe329e23
Primary Citations — 7 traced to source
- MITRE ATT&CK for ICS Technique T0873: Project File Infection (https://attack.mitre.org/techniques/T0873/)
- MITRE ATT&CK ICS Tactic TA0110: Persistence (https://attack.mitre.org/tactics/TA0110/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.