MITRE ATT&CK® Matrix
Mobile ATT&CK Matrix
A Glexia-styled visualization of ATT&CK tactics and techniques. This is not the MITRE Navigator UI and does not imply MITRE endorsement.
Collection
24 techniques
T1409Stored Application DataAndroid, iOST1414Clipboard DataAndroid, iOST1417Input CaptureAndroid, iOST1417.001KeyloggingAndroid, iOST1417.002GUI Input CaptureAndroid, iOST1429Audio CaptureAndroid, iOST1430Location TrackingAndroid, iOST1430.001Remote Device Management ServicesAndroid, iOST1430.002Impersonate SS7 NodesAndroid, iOST1453Abuse Accessibility FeaturesAndroidT1512Video CaptureAndroid, iOST1513Screen CaptureAndroidT1517Access NotificationsAndroidT1532Archive Collected DataAndroid, iOST1533Data from Local SystemAndroid, iOST1616Call ControlAndroidT1636Protected User DataAndroid, iOST1636.001Calendar EntriesAndroid, iOST1636.002Call LogAndroid, iOST1636.003Contact ListAndroid, iOST1636.004SMS MessagesAndroid, iOST1636.005AccountsAndroid, iOST1638Adversary-in-the-MiddleAndroid, iOST1676Linked DevicesAndroid, iOS
Command and Control
17 techniques
T1437Application Layer ProtocolAndroid, iOST1437.001Web ProtocolsAndroid, iOST1481Web ServiceAndroid, iOST1481.001Dead Drop ResolverAndroid, iOST1481.002Bidirectional CommunicationAndroid, iOST1481.003One-Way CommunicationAndroid, iOST1509Non-Standard PortAndroid, iOST1521Encrypted ChannelAndroid, iOST1521.001Symmetric CryptographyAndroid, iOST1521.002Asymmetric CryptographyAndroid, iOST1521.003SSL PinningAndroid, iOST1544Ingress Tool TransferAndroid, iOST1616Call ControlAndroidT1637Dynamic ResolutionAndroid, iOST1637.001Domain Generation AlgorithmsAndroid, iOST1644Out of Band DataAndroid, iOST1663Remote Access SoftwareAndroid, iOS
Credential Access
10 techniques
T1414Clipboard DataAndroid, iOST1417Input CaptureAndroid, iOST1417.001KeyloggingAndroid, iOST1417.002GUI Input CaptureAndroid, iOST1453Abuse Accessibility FeaturesAndroidT1517Access NotificationsAndroidT1634Credentials from Password StoreiOST1634.001KeychainiOST1635Steal Application Access TokenAndroid, iOST1635.001URI HijackingAndroid, iOS
Defense Evasion
33 techniques
T1406Obfuscated Files or InformationAndroid, iOST1406.001SteganographyAndroidT1406.002Software PackingAndroid, iOST1407Download New Code at RuntimeAndroid, iOST1516Input InjectionAndroidT1541Foreground PersistenceAndroidT1575Native APIAndroidT1604Proxy Through VictimAndroidT1617HookingAndroidT1627Execution GuardrailsAndroid, iOST1627.001GeofencingAndroid, iOST1628Hide ArtifactsAndroidT1628.001Suppress Application IconAndroidT1628.002User EvasionAndroidT1628.003Conceal Multimedia FilesAndroidT1629Impair DefensesAndroidT1629.001Prevent Application RemovalAndroidT1629.002Device LockoutAndroidT1629.003Disable or Modify ToolsAndroidT1630Indicator Removal on HostiOS, AndroidT1630.001Uninstall Malicious ApplicationAndroidT1630.002File DeletionAndroidT1630.003Disguise Root/Jailbreak IndicatorsAndroid, iOST1631Process InjectionAndroid, iOST1631.001Ptrace System CallsAndroid, iOST1632Subvert Trust ControlsAndroid, iOST1632.001Code Signing Policy ModificationAndroid, iOST1633Virtualization/Sandbox EvasionAndroid, iOST1633.001System ChecksAndroid, iOST1655MasqueradingAndroid, iOST1655.001Match Legitimate Name or LocationAndroid, iOST1661Application VersioningAndroid, iOST1670Virtualization SolutionAndroid
Discovery
13 techniques
T1418Software DiscoveryAndroid, iOST1418.001Security Software DiscoveryAndroid, iOST1420File and Directory DiscoveryAndroid, iOST1421System Network Connections DiscoveryAndroidT1422System Network Configuration DiscoveryAndroid, iOST1422.001Internet Connection DiscoveryAndroid, iOST1422.002Wi-Fi DiscoveryAndroid, iOST1423Network Service ScanningAndroid, iOST1424Process DiscoveryAndroid, iOST1426System Information DiscoveryAndroid, iOST1430Location TrackingAndroid, iOST1430.001Remote Device Management ServicesAndroid, iOST1430.002Impersonate SS7 NodesAndroid, iOS
Execution
5 techniques
Exfiltration
3 techniques
Impact
11 techniques
T1464Network Denial of ServiceAndroid, iOST1471Data Encrypted for ImpactAndroidT1516Input InjectionAndroidT1582SMS ControlAndroidT1616Call ControlAndroidT1640Account Access RemovalAndroidT1641Data ManipulationAndroidT1641.001Transmitted Data ManipulationAndroidT1642Endpoint Denial of ServiceAndroid, iOST1643Generate Traffic from VictimAndroid, iOST1662Data DestructionAndroid
Initial Access
11 techniques
T1451SIM Card SwapAndroid, iOST1456Drive-By CompromiseAndroid, iOST1458Replication Through Removable MediaAndroid, iOST1461Lockscreen BypassAndroid, iOST1474Supply Chain CompromiseAndroid, iOST1474.001Compromise Software Dependencies and Development ToolsAndroid, iOST1474.002Compromise Hardware Supply ChainAndroid, iOST1474.003Compromise Software Supply ChainAndroid, iOST1660PhishingAndroid, iOST1661Application VersioningAndroid, iOST1664Exploitation for Initial AccessAndroid, iOS
Lateral Movement
2 techniques
Persistence
10 techniques
T1398Boot or Logon Initialization ScriptsAndroid, iOST1541Foreground PersistenceAndroidT1577Compromise Application ExecutableAndroidT1603Scheduled Task/JobAndroid, iOST1624Event Triggered ExecutionAndroidT1624.001Broadcast ReceiversAndroidT1625Hijack Execution FlowAndroidT1625.001System Runtime API HijackingAndroidT1645Compromise Client Software BinaryAndroid, iOST1676Linked DevicesAndroid, iOS
Privilege Escalation
5 techniques
Exports
Structured JSON, CSV, and Navigator-layer export generation will use the normalized reference records after full sync. The current page is intentionally lightweight and source-backed.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
