Skip to content
CIM-257 Cyber Incidents & Offender Methods

What is a compromised software update?

A compromised software update is a legitimate-looking update that has been altered, replaced or produced through a compromised development or delivery process.

Evidential caution: that every system receiving the update was compromised in the same way.

What this means

Some systems may:

download but not install it;

install but not execute the malicious component;

block it;

receive a different version;

apply the update after the malicious period ended;

lack the vulnerable configuration.

the affected version;

download and installation time;

source;

signature;

execution;

process and network activity;

systems that received it;

systems that actually ran it;

what later actions followed.

The update mechanism may preserve deployment logs even where endpoint artefacts are limited.

A device may list the version without having executed the malicious code.

Likewise, execution may have occurred even where the package was later removed.

The supplier may also be a victim rather than a knowing participant.

Where the update was distributed through several channels, identify which channel each device used. Direct vendor download, managed deployment, package repository and cached local source may preserve different records. This can help show whether the malicious package came from the supplier, an intermediary or a compromised internal deployment system.

A compromised update may also contain dormant code that activates only under certain conditions. Preserve configuration, environment checks and later command traffic. Installation alone may show exposure, while activation and resulting behaviour establish actual compromise. The operational takeaway is:

Separate update availability, download, installation, execution and resulting activity for each system, and keep supplier involvement distinct from offender control.

================================================================================

What to check or do next

  • Investigators should establish:
  • Do not infer compromise solely from software inventory.

Evidential limits

It may not have been.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.