{"id":49070,"date":"2022-10-28T00:00:00","date_gmt":"2022-10-28T00:00:00","guid":{"rendered":"urn:uuid:c4f46315-0c7e-d1d9-7500-a570a6da6cbc"},"modified":"2022-10-28T00:00:00","modified_gmt":"2022-10-28T00:00:00","slug":"comprehensive-traceability-for-android-supply-chain-security","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/","title":{"rendered":"Comprehensive Traceability for Android Supply-Chain Security"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/android-supply-chain-tn.png\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/android-supply-chain-tn.png\" class=\"ff-og-image-inserted\"><\/div>\n<p><b><i>What is product traceability?<\/i><\/b><\/p>\n<p>Product supply-chain traceability is a very important aspect in manufacturing as it contributes directly to product safety, quality, and, as an emerging trend, product sustainability and ethics.<\/p>\n<p>In terms of safety, automotive manufacturers consistently announce product recalls to protect their customers from failure of faulty parts, as well as to protect themselves by being compliant and avoiding litigation. In a recent example, Rivian, an electric car company, recently issued a recall of all its vehicles due to a loose fastener for its steering.&nbsp;<\/p>\n<p>Brand reputation is also a major driver for product traceability. For example, luxury jewelers make sure the diamonds they sell have a Kimberley Process Certificate to ensure that these are not blood diamonds (diamonds that are mined by exploiting workers and the environment).&nbsp;<\/p>\n<p>In the software industry, however, traceability is still currently a weak point. For example, the Log4j vulnerability became a sticky issue for cybersecurity teams as the major challenge it presented them with was not to fix and patch the vulnerability, but rather to identify which software in their environment was using Log4j in the first place. This is the reason that the idea of having a software bill of materials (SBOM) is gaining traction \u2014 so that the whole industry can build traceability on software products.<\/p>\n<p>Traceability in the Android ecosystem is an even bigger challenge due to its open architecture, as Android is designed to run on a wide range of mobile devices and vendors are allowed to create their own variants of the operating system. Most smartphone brands also do not have in-house expertise to produce all necessary components, such as the hardware, firmware, apps, and infrastructure for system updates, so many Android smartphone devices are just rebranded from OEMs. Because of this, many Android brands do not have the slightest idea what went into the product they are selling and have been caught unaware when unwanted apps and security issues affected their products.<\/p>\n<p><b><i>The problem with the Android software supply chain<\/i><\/b><\/p>\n<p>Suppose that ACME telco (a fictitious company) wants to package a cheap smartphone into their subscription plans in order to push a new 5G data plan to the market. As ACME telco is not a smartphone manufacturer, ACME will outsource development and manufacturing of the device to an OEM vendor. All ACME needs to do is provide the expected spec, target price, and branding. This process is often referred to as \u201cwhite labeling,\u201d with the name coming from the fact that the OEM takes complete responsibility for producing the device and simply leaves the brand label \u201cwhite,\u201d to be filled in by its customer.<\/p>\n<p>Such convenience and cost cutting do not come without risks. The OEM will of course try to use the cheapest components that meet the specifications. And since smartphones don\u2019t just run on hardware alone, firmware and custom apps in the device also have associated costs, which the OEM will cost-optimize as well. Firmware developers supplying the OEM might agree to provide the software at a lower cost because they can compensate the lost profit through questionable means, for example by discreetly pre-installing apps from other app developers for a fee. There is a whole market built around this bundling service with prices ranging from 1 to 10 Chinese yuan (approximately US$0.14 to US$1.37 as of this writing) <a href=\"https:\/\/www.cnblogs.com\/anf\/p\/5071787.html\">per application per device<\/a>. This is where the risk is: As long as the firmware, packaged apps, and update mechanisms of the device are not owned, controlled, or audited by the smartphone brand itself, a rogue supplier can hide unauthorized code therein.<\/p>\n<p>Furthermore, the malicious or unwanted code does not necessarily need to be fully installed during manufacturing. As smartphones are internet-connected anyway, the firmware and app update mechanisms of the device can be leveraged by rogue suppliers to install the malicious or unwanted code later, when the device is in actual use.&nbsp; &nbsp;<\/p>\n<p>If the OEM lacks supplier visibility, component tracking, and integrity checks, this makes it difficult to track the rogue supplier responsible for the unauthorized code and determine when the code was bundled into the product. The abuse of the firmware and app update mechanisms also means that the groups behind the operation can be selective in deploying whatever unauthorized app or code they want to inject into the device at whatever time they choose, which makes diagnostics, incident response, and forensics much more complicated.<\/p>\n<p><b><i>Why is Android supply-chain security important?<\/i><\/b><\/p>\n<p>Gone are the days when a smartphone is just a phone with a camera that you can use to play games, listen to music, and watch movies. A modern smartphone is almost always connected to the internet (thanks to mobile data plans getting cheaper and cheaper) and runs productivity and enterprise apps so you can do actual work on it.&nbsp;<\/p>\n<p>Furthermore, smartphones have a mobile number that is then tied to online identities, either as part of two-factor authentication (2FA) or for checking the validity of an account. Aside from SMS-based 2FA, authentication apps used in corporate authentication systems are also done using smartphones apps.<\/p>\n<p><b><i>What should we do?<\/i><\/b><\/p>\n<p>As Android phone users, if the smartphone is so important to our day-to-day tasks, shouldn\u2019t we be more aware of the provenance of the components and software running in our smartphones?<\/p>\n<p>Second, shouldn\u2019t smartphone vendors exercise greater due diligence in sourcing their devices, deal only with vetted OEMs, and require product traceability and an SBOM?<\/p>\n<p>Third, as infosec professionals, shouldn\u2019t we review and vet which brand and models are acceptable before allowing enterprise and authentication apps to be installed on them?<\/p>\n<p>These are the questions that we need to ask ourselves as there is currently no specific guideline or certification body to ascertain the integrity of Android smartphones and their firmware. We need to apply various levels of vendor and device accreditation depending on risk appetite to make sure that all devices are purchased from reputable brands who secure their supply chains and vet their suppliers.<\/p>\n<p>Government bodies can also help encourage manufacturers and retailers by creating schemes that highlight products that are compliant to secure manufacturing and development practices.&nbsp; For example, Singapore and Finland have a Cybersecurity Labeling Scheme that offers a simplified overview of a product\u2019s cybersecurity resilience through a four-level rating that involves checks on basic security, developer\u2019s declaration of conformance, third-party assessment, and penetration testing. While the current implementation only covers internet-of-things (IoT) devices such as routers and IP cameras, a similar scheme can be extended to cover smartphones.<\/p>\n<p>As of today, rogue suppliers can remain hidden and continue their unethical business practices because there is no visibility over these. And because there is no visibility, accountability is difficult to enforce. Increasing visibility through product traceability, an SBOM, and even government-supported assessment schemes will effectively narrow the window of opportunity for these rogue suppliers to hide.<\/p>\n<p><i>From Fyodor Yarochkin, Vladimir Kropotov, Zhengyu Dong, Paul Pajares, and Ryan Flores<\/i><\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/j\/comprehensive-traceability-for-android-supply-chain-security.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We discuss the importance of traceability in the world of mobile operating systems. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":49071,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9538,9581,9509],"class_list":["post-49070","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-compliancerisks","tag-trend-micro-research-mobile","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-28T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/android-supply-chain-tn.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Comprehensive Traceability for Android Supply-Chain Security\",\"datePublished\":\"2022-10-28T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/\"},\"wordCount\":1169,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/comprehensive-traceability-for-android-supply-chain-security.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Compliance&amp;Risks\",\"Trend Micro Research : Mobile\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/\",\"name\":\"Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/comprehensive-traceability-for-android-supply-chain-security.png\",\"datePublished\":\"2022-10-28T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/comprehensive-traceability-for-android-supply-chain-security.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/10\\\/comprehensive-traceability-for-android-supply-chain-security.png\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/comprehensive-traceability-for-android-supply-chain-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Comprehensive Traceability for Android Supply-Chain Security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/","og_locale":"en_US","og_type":"article","og_title":"Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-10-28T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/android-supply-chain-tn.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Comprehensive Traceability for Android Supply-Chain Security","datePublished":"2022-10-28T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/"},"wordCount":1169,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/comprehensive-traceability-for-android-supply-chain-security.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Compliance&amp;Risks","Trend Micro Research : Mobile","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/","url":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/","name":"Comprehensive Traceability for Android Supply-Chain Security 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/comprehensive-traceability-for-android-supply-chain-security.png","datePublished":"2022-10-28T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/comprehensive-traceability-for-android-supply-chain-security.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/10\/comprehensive-traceability-for-android-supply-chain-security.png","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/comprehensive-traceability-for-android-supply-chain-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Comprehensive Traceability for Android Supply-Chain Security"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=49070"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49070\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/49071"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=49070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=49070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=49070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}