Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK Mobile T1474: Supply Chain Compromise (Initial Access)

MITRE ATT&CK Mobile T1474 covers adversary compromise of mobile applications through the software supply chain - malicious code injected into Google Play…

What MITRE ATT&CK Mobile T1474: Supply Chain Compromise (Initial Access) requires

MITRE ATT&CK Mobile T1474 covers adversary compromise of mobile applications through the software supply chain - malicious code injected into Google Play / Apple App Store apps, sideloaded APK distribution, third-party SDK compromise, and tampered firmware. Pegasus (NSO Group), Predator (Intellexa), and the 2023 3CX desktop-mobile supply chain compromise are notable examples. Compliance obligations include NIST SP 800-124 Rev 2 (Mobile Device Security), NIST SP 800-218 (SSDF), ISO 27001 A.5.20-A.5.23, FDA Pre-Market Cybersecurity Guidance for medical mobile apps, HIPAA Security Rule mobile risk analysis, and EU Cyber Resilience Act for mobile components.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1474/

SHA-256 integrity: a81b6a4a64d628425e4bfa598197cc903392dfdef70c55bb6dc220cb7e89ec0b

Primary Citations — 8 traced to source

  • MITRE ATT&CK Mobile Technique T1474: Supply Chain Compromise (https://attack.mitre.org/techniques/T1474/)
  • NIST SP 800-124 Rev 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.