Activity timeline
T1195.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1195.003 Compromise Hardware Supply Chain is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of T1195 Supply Chain Compromise. Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 7 critical, 5 high, 1 medium.
Threats that use T1195.003 most often also use T1071.001 Web Protocols (8 threats), T1005 Data from Local System (6 threats), T1027 Obfuscated Files or Information (6 threats), T1036.005 Match Legitimate Resource Name or Location (6 threats), T1041 Exfiltration Over C2 Channel (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1195.003; the most frequent are LenAI (1), Shai-Hulud (1), Storm-2945 (1), TeamPCP (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1195.003.
Data sources
Telemetry that can reveal T1195.003, per MITRE ATT&CK.
- Sensor Health — Host Status
Threat actors using it
Tracked threats
15 tracked threats use T1195.003.
- Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Addressmedium
- WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedureshigh
- Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stationshigh
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Modelscritical
- COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theftcritical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Executive Order: Defense Contractors Ordered to Map Software Suppliers Across Critical Supply Chains…
- Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
- Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…high
- CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)critical
- ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…high
- Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packagescritical
- Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCPcritical
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…critical
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1195.003 (SPL 8, KQL 10, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1195 Supply Chain Compromise — 333 tracked threats at the technique level.