LiveActive security incident?Get immediate response
MITRE ATT&CK® Matrix

Mobile ATT&CK Matrix

A Glexia-styled visualization of ATT&CK tactics and techniques. This is not the MITRE Navigator UI and does not imply MITRE endorsement.

Matrix workbench

124 techniques and sub-techniques mapped across 12 tactics

Use this as a fast defensive coverage map. Each cell links to the normalized Glexia detail page with official source attribution and relationship context.

TA0035

Collection

24 techniques

T1409Stored Application DataAndroid, iOST1414Clipboard DataAndroid, iOST1417Input CaptureAndroid, iOST1417.001KeyloggingAndroid, iOST1417.002GUI Input CaptureAndroid, iOST1429Audio CaptureAndroid, iOST1430Location TrackingAndroid, iOST1430.001Remote Device Management ServicesAndroid, iOST1430.002Impersonate SS7 NodesAndroid, iOST1453Abuse Accessibility FeaturesAndroidT1512Video CaptureAndroid, iOST1513Screen CaptureAndroidT1517Access NotificationsAndroidT1532Archive Collected DataAndroid, iOST1533Data from Local SystemAndroid, iOST1616Call ControlAndroidT1636Protected User DataAndroid, iOST1636.001Calendar EntriesAndroid, iOST1636.002Call LogAndroid, iOST1636.003Contact ListAndroid, iOST1636.004SMS MessagesAndroid, iOST1636.005AccountsAndroid, iOST1638Adversary-in-the-MiddleAndroid, iOST1676Linked DevicesAndroid, iOS
TA0037

Command and Control

17 techniques

TA0031

Credential Access

10 techniques

TA0030

Defense Evasion

33 techniques

T1406Obfuscated Files or InformationAndroid, iOST1406.001SteganographyAndroidT1406.002Software PackingAndroid, iOST1407Download New Code at RuntimeAndroid, iOST1516Input InjectionAndroidT1541Foreground PersistenceAndroidT1575Native APIAndroidT1604Proxy Through VictimAndroidT1617HookingAndroidT1627Execution GuardrailsAndroid, iOST1627.001GeofencingAndroid, iOST1628Hide ArtifactsAndroidT1628.001Suppress Application IconAndroidT1628.002User EvasionAndroidT1628.003Conceal Multimedia FilesAndroidT1629Impair DefensesAndroidT1629.001Prevent Application RemovalAndroidT1629.002Device LockoutAndroidT1629.003Disable or Modify ToolsAndroidT1630Indicator Removal on HostiOS, AndroidT1630.001Uninstall Malicious ApplicationAndroidT1630.002File DeletionAndroidT1630.003Disguise Root/Jailbreak IndicatorsAndroid, iOST1631Process InjectionAndroid, iOST1631.001Ptrace System CallsAndroid, iOST1632Subvert Trust ControlsAndroid, iOST1632.001Code Signing Policy ModificationAndroid, iOST1633Virtualization/Sandbox EvasionAndroid, iOST1633.001System ChecksAndroid, iOST1655MasqueradingAndroid, iOST1655.001Match Legitimate Name or LocationAndroid, iOST1661Application VersioningAndroid, iOST1670Virtualization SolutionAndroid
TA0032

Discovery

13 techniques

TA0041

Execution

5 techniques

TA0036

Exfiltration

3 techniques

TA0034

Impact

11 techniques

TA0027

Initial Access

11 techniques

TA0033

Lateral Movement

2 techniques

TA0028

Persistence

10 techniques

TA0029

Privilege Escalation

5 techniques

Exports

Structured JSON, CSV, and Navigator-layer export generation will use the normalized reference records after full sync. The current page is intentionally lightweight and source-backed.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.