# T1195.003 Compromise Hardware Supply Chain

> As of 2026-10-05, T1195.003 (Compromise Hardware Supply Chain) appears in 15 tracked threats, first reported 2026-02-05 and most recently 2026-08-10, with linked actors including LenAI, Shai-Hulud, Storm-2945; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 15 (7 critical, 5 high, 1 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-08-10
- **Threat actors:** 4
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1195.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access
- **Matrix:** Enterprise
- **Parent:** T1195
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1195/003/

## Activity timeline

T1195.003 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-08-10. The busiest month was 2026-07 with 6 reports, and 15 of the 15 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1195.003 Compromise Hardware Supply Chain is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix, as a sub-technique of [T1195 Supply Chain Compromise](https://intel.threadlinqs.com/technique/T1195). Threadlinqs maps 15 of 2623 tracked threats (0.6%) to it; by severity that is 7 critical, 5 high, 1 medium.

Threats that use T1195.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (8 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (6 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (6 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (6 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1195.003; the most frequent are [LenAI](https://intel.threadlinqs.com/actor/LenAI) (1), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (1), [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) (1), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1195.003.

- [M1046 Boot Integrity](https://attack.mitre.org/mitigations/M1046/)

## Data sources

Telemetry that can reveal T1195.003, per MITRE ATT&CK.

- Sensor Health — Host Status

## Threat actors using it

- [LenAI](https://intel.threadlinqs.com/actor/LenAI) — 1
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1

## Tracked threats

15 tracked threats use T1195.003.

- [Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address](https://intel.threadlinqs.com/threat/TL-2026-1975) — medium — 2026-08-10
- [WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures](https://intel.threadlinqs.com/threat/TL-2026-1966) — high — 2026-08-10
- [Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations](https://intel.threadlinqs.com/threat/TL-2026-1911) — high — 2026-08-06
- [ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models](https://intel.threadlinqs.com/threat/TL-2026-1906) — critical — 2026-08-06
- [COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1822) — critical — 2026-08-02
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Executive Order: Defense Contractors Ordered to Map Software Suppliers Across Critical Supply Chains…](https://intel.threadlinqs.com/threat/TL-2026-1591) — 2026-07-21
- [Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)](https://intel.threadlinqs.com/threat/TL-2026-1250) — 2026-07-13
- [Counterfeit China-Made USB Drives with Self-Replicating Malware Infect 50+ Japan Ground Self-Defense Force…](https://intel.threadlinqs.com/threat/TL-2026-1240) — high — 2026-07-11
- [CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)](https://intel.threadlinqs.com/threat/TL-2026-1188) — critical — 2026-07-10
- [ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via…](https://intel.threadlinqs.com/threat/TL-2026-0817) — high — 2026-06-16
- [Atomic Arch: AUR Package Supply Chain Compromise Using Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-0979) — critical — 2026-06-12
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas…](https://intel.threadlinqs.com/threat/TL-2026-0098) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1195.003, most frequent first.

- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1195.003 (SPL 8, KQL 10, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1195 Supply Chain Compromise](https://intel.threadlinqs.com/technique/T1195) — 333 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1195.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
