Compliance Node Overview
MITRE ATT&CK T1474.003 (Compromise Software Supply Chain) is an ATT&CK for Mobile Initial Access sub-technique of T1474 (Supply Chain Compromise). Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version. Affected platforms: Android, iOS. MITRE-documented mitigations include M1004 System Partition Integrity, M1001 Security Updates. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1474/003/
SHA-256 integrity: add6571e752da241e047575dbd6919110e1fb7a74d48f46994e8a0600519263e
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1474.003: Compromise Software Supply Chain (https://attack.mitre.org/techniques/T1474/003/)
- MITRE ATT&CK Mobile Tactic TA0027: Initial Access (https://attack.mitre.org/tactics/TA0027/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.