Ankara: State-sponsored cyber threat groups are increasingly using subcontractor firms with security vulnerabilities to reach major targets that they cannot access directly, prompting a greater emphasis on global cooperation and layered defense strategies against such threats. Supply chain attacks aim to infiltrate large targets indirectly by compromising third parties such as software developers, hardware suppliers, or service providers. In recent years, malicious code embedded into software updates or remote access tools has exposed thousands of organizations and leaked the personal data of millions.
According to Anadolu Agency, this attack method, first brought to global attention by the SolarWinds breach in 2020, allows threat actors to access multiple targets from a single entry point. Dmitry Galov, the head of Kaspersky's Global Research and Analysis Team, told Anadolu that tactics employed by Advanced Persistent Threat actors -- often state-backed groups -- have become significantly more sophisticated over the past year.
Referring to the XZ vulnerability that recently affected thousands of Linux servers, Galov said attackers spent years manipulating developers behind the open-source XZ Utils software. The result was a covert backdoor capable of bypassing SSH authentication, giving threat actors remote access to systems. 'Every supply chain attack is so different and so tailored to the specific victim that is interesting for the potential attacker, that we cannot foresee how they will act next time,' Galov said.
Galov explained that attackers spent several years on social engineering, pushing developers and maintainers of an open-source library that was interesting to them, just before moving to the technical part of backdooring something. To counter such threats, Kaspersky uses behavioral analysis and AI-based detection technologies that can identify and block malicious payloads -- even when delivered through seemingly trusted software.
Galov emphasized that supply chain attacks often begin with smaller subcontractors. He noted that attackers know major companies have strong cybersecurity defenses. 'Instead of going directly, they play a two-step game. First, they compromise a subcontractor -- whose defenses are typically weaker -- and then pivot to the real target,' he said. Galov advised that large companies evaluate the cybersecurity posture of their vendors, including through penetration testing, and implement strict auditing of all incoming software.
He further noted that Kaspersky has developed a scanner for open-source libraries to help identify malicious code in widely used development packages. Galov described the ongoing struggle between defenders and attackers as 'a race,' highlighting the need for global cooperation and threat intelligence sharing. He concluded with a warning that no single technology can solve supply chain threats, requiring layered defense and cooperation among governments, cybersecurity companies, and users.