3 ms·
Attackers do what makes money. A lot of that is market driven - you buy what exploits are available, what tools are available, etc. You monetize in a fairly sta
by staticassertion 4y ago
Attackers do what makes money. A lot of that is market driven - you buy what exploits are available, what tools are available, etc. You monetize in a fairly standard way. Attackers aren't all just random people thinking "oh I could hack that" - that's a tiny minority of them.
Eventually, due to a lot of factors, threat landscapes start shifting and attackers start moving their targets and tooling. One of the bigger shifts would be the huge, rapid improvement to both OS and browser security that occurred within a few years, radically increasing the cost of attacking desktop users via malicious websites. Another would be crypto, where 'account takeover' attacks that could lead to wallet access are now easier to monetize + crypto itself as a tool for transfers.
With regards to supply chain, enough of these changes occurred that some attackers took the leap and have started looking at this area. There are probably a lot of reasons why - prevalence of dependencies, increased interest in tech companies, etc.
If it continues to prove viable (it's obviously viable from an attack perspective, unclear if it's something attackers will rally around to monetize) we'll see it escalate and get better tooling around the attacks.