CAPEC-185: Malicious Software Download
An attacker uses deceptive methods to cause a user or an automated process to download and install dangerous code that originates from an attacker controlled source. There are several variations to this strategy of attack.
Last updated
Overview
CAPEC-185 (Malicious Software Download) is a standard-level attack pattern catalogued by MITRE in the Common Attack Pattern Enumeration and Classification (CAPEC). It describes a recurring method attackers use to exploit software weaknesses.
Frequently asked questions
Common questions about CAPEC-185.
- What is CAPEC-185?
- An attacker uses deceptive methods to cause a user or an automated process to download and install dangerous code that originates from an attacker controlled source. There are several variations to this strategy of attack.
- What weaknesses does CAPEC-185 target?
- CAPEC-185 exploits 1 CWE weakness, including CWE-494 (Download of Code Without Integrity Check).
- How severe is CAPEC-185?
- MITRE rates CAPEC-185 as Very High severity.
References
Attack-pattern data is sourced from the MITRE CAPEC catalog (v3.9). Weakness associations link to the corresponding CWE entries on RadicalNotion.AI.
Defend against CAPEC-185
Track the CVEs and weaknesses attackers exploit with this technique, with AI-written analysis and remediation guidance.