What MITRE ATT&CK Mobile T1474: Supply Chain Compromise (Initial Access) requires
MITRE ATT&CK Mobile T1474 covers adversary compromise of mobile applications through the software supply chain - malicious code injected into Google Play / Apple App Store apps, sideloaded APK distribution, third-party SDK compromise, and tampered firmware. Pegasus (NSO Group), Predator (Intellexa), and the 2023 3CX desktop-mobile supply chain compromise are notable examples. Compliance obligations include NIST SP 800-124 Rev 2 (Mobile Device Security), NIST SP 800-218 (SSDF), ISO 27001 A.5.20-A.5.23, FDA Pre-Market Cybersecurity Guidance for medical mobile apps, HIPAA Security Rule mobile risk analysis, and EU Cyber Resilience Act for mobile components.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1474/
SHA-256 integrity: a81b6a4a64d628425e4bfa598197cc903392dfdef70c55bb6dc220cb7e89ec0b
Primary Citations — 8 traced to source
- MITRE ATT&CK Mobile Technique T1474: Supply Chain Compromise (https://attack.mitre.org/techniques/T1474/)
- NIST SP 800-124 Rev 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-mobile-t1474-supply-chain-compromise.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-mobile-t1474-supply-chain-compromise.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-mobile-t1474-supply-chain-compromise
- Back to registry: Browse all 10,085 compliance nodes