Invalid Digital Signature in On-Orbit Update Package

Detection of an invalid digital signature in the on-orbit update package, potentially indicating tampering or replacement of the legitimate update with a malicious version before it is sent to the spacecraft. This is assuming digital signatures are being used on the spacecraft.

STIX Pattern

[x-opencti-software:signature_validity = 'invalid' AND x-opencti-software:name = 'on_orbit_update_package']

SPARTA TTPs

ID Name Description
IA-0001 Compromise Supply Chain Threat actors may manipulate or compromise products or product delivery mechanisms before the customer receives them in order to achieve data or system compromise.
IA-0001.02 Software Supply Chain Threat actors may manipulate software binaries and applications prior to the customer receiving them in order to achieve data or system compromise. This attack can take place in a number of ways, including manipulation of source code, manipulation of the update and/or distribution mechanism, or replacing compiled versions with a malicious one.
IA-0007.01 Compromise On-Orbit Update Threat actors may manipulate and modify on-orbit updates before they are sent to the target spacecraft. This attack can be done in a number of ways, including manipulation of source code, manipulating environment variables, on-board table/memory values, or replacing compiled versions with a malicious one.