{
  "id": "case-xz-backdoor",
  "slug": "xz-utils-backdoor-liblzma",
  "title": "XZ Utils liblzma Upstream Linux Supply Chain Backdoor (CVE-2024-3094)",
  "summary": "Sophisticated multi-year social engineering and software supply chain operation where persona Jia Tan gained co-maintainer status on the foundational open-source xz compression project, embedding a multi-stage obfuscated backdoor into liblzma tarballs that hijacked OpenSSH sshd authentication to enable unauthorized pre-auth remote code execution.",
  "case_number": "CVE-2024-3094",
  "court": "Cybersecurity and Infrastructure Security Agency Alert",
  "district": "Global / Open Source",
  "country": "International",
  "opened_at": "2024-03-29",
  "status": "investigation",
  "victim_sector": "Open Source Software & Linux Ecosystem",
  "victim_country": "Global",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "Global developer triage, emergency distribution downgrades, and open-source maintainer security reviews.",
  "first_seen_at": "2021-10-18T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "unattributed-state-actor",
  "defendant_slugs": [],
  "cves": [
    "CVE-2024-3094"
  ],
  "techniques": [
    {
      "technique_id": "T1195.001",
      "evidence_excerpt": "The attacker inserted malicious M4 macros into build test files during tarball release generation, modifying the build pipeline to inject binary code into liblzma.so.",
      "evidence_locator": "Openwall Disclosure by Andres Freund",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Openwall security announcement: backdoor in upstream xz/liblzma leading to sshd compromise",
      "source_url": "https://www.openwall.com/lists/oss-security/2024/03/29/4"
    },
    {
      "technique_id": "T1574.006",
      "evidence_excerpt": "The backdoor hooked the OpenSSH RSA_public_decrypt function via ELF indirect functions (IFUNC) before main execution, allowing custom signed payloads to bypass authentication.",
      "evidence_locator": "CISA Alert AL24-089A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert: Reported Supply Chain Compromise Affecting XZ Utils",
      "source_url": "https://www.cisa.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-02-23",
      "description": "Jia Tan pushes commits containing backdoored release tarballs xz-5.6.0 and xz-5.6.1."
    },
    {
      "event_type": "discovery",
      "event_date": "2024-03-29",
      "description": "PostgreSQL developer Andres Freund discovers CPU micro-benchmarking latency anomalies in sshd, exposing the backdoor."
    },
    {
      "event_type": "advisory",
      "event_date": "2024-03-29",
      "description": "CISA issues emergency advisory urging immediate downgrade of Linux packages."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-3094) combined with targeted spearphishing and stolen remote access credentials.",
    "blast_radius": "Global developer triage, emergency distribution downgrades, and open-source maintainer security reviews. Impacted Open Source Software & Linux Ecosystem infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Open Source Software & Linux Ecosystem sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Sophisticated multi-year social engineering and software supply chain operation where persona Jia Tan gained co-maintainer status on the foundational open-source xz compression project, embedding a multi-stage obfuscated backdoor into liblzma tarballs that hijacked OpenSSH sshd authentication to enable unauthorized pre-auth remote code execution.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}