LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1409: Stored Application Data

Adversaries may try to access and collect application data resident on the device. Adversaries often target popular applications, such as Facebook, WeChat, and Gmail.[1]

Due to mobile OS sandboxing, this technique is only possible in three scenarios:

* An application stores files in unprotected external storage * An application stores files in its internal storage directory with insecure permissions (e.g. 777) * The adversary gains root permissions on the device

MobileT1409TechniqueObject v3.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Stored Application Data matters because mobile devices often hold business communications, identity material, email, messaging content, and application-local records that may not be visible in traditional endpoint monitoring. ATT&CK describes this as adversaries attempting to access application data resident on Android or iOS devices, especially popular apps, when storage is exposed, permissions are insecure, or the device is rooted or jailbroken. For leaders, the decision point is not only malware detection; it is whether mobile app storage, OS currency, and managed-device visibility are strong enough to protect sensitive data on phones and tablets.

Executive priority

Prioritize this technique where mobile devices are used for executive communications, regulated data access, privileged administration, or workforce identity workflows. The supplied ATT&CK relationships show broad use across mobile spyware, banking malware, and surveillanceware families, plus an iOS campaign relationship, making it a useful control-validation scenario for mobile security programs. Executives should ask whether managed devices run recent OS versions, whether high-risk apps store data safely, whether rooted or jailbroken devices are blocked from business access, and whether incident responders can collect enough mobile evidence to confirm or rule out application-data access.

Technical view

For SOC, detection engineering, and IR teams, validate coverage on Android and iOS for evidence that application-resident data could be accessed outside normal app boundaries. ATT&CK states this is constrained by mobile OS sandboxing and is primarily possible when apps store files in unprotected external storage, use insecure permissions in internal storage, or when adversaries gain root permissions. Because ATT&CK provides no official detection text for T1409, teams should treat related detection strategy DET0621 as a pointer to build local analytics around storage exposure, app permission weakness, device integrity state, and suspicious access to app data paths. Relationship context includes many Android software entries, several iOS or cross-platform entries, and Operation Triangulation on iOS, so testing should not be limited to one mobile OS if both are in scope.

Likely telemetry

  • Mobile device management or enterprise mobility inventory showing Android/iOS version, patch level, device compliance, and managed/unmanaged status
  • Root or jailbreak indicators from MDM, mobile threat defense, or device compliance checks
  • Application inventory and app risk assessment results, especially for business-critical messaging, email, banking, wallet, shopping, and collaboration apps
  • Mobile application security test results showing use of external storage, insecure file permissions, or sensitive local data storage
  • On-device forensic artifacts during incident response, including application data locations and file permission evidence where legally and technically available

Detection direction

  • Start by confirming whether DET0621 or an equivalent local detection strategy is implemented; ATT&CK does not provide a native detection description for T1409.
  • Tune detection around prerequisites and enabling conditions: rooted or jailbroken devices, apps storing sensitive files in external storage, and insecure internal storage permissions.
  • Correlate mobile malware or spyware detections with device posture and app data exposure rather than treating the malware alert alone as proof of data access.
  • Account for blind spots on personally owned or unmanaged devices, where storage inspection, app inventory, and forensic collection may be limited.
  • Use relationship context for threat-informed testing: ATT&CK links this technique to Pegasus for iOS, Pegasus for Android, RCSAndroid, SpyDealer, Skygofree, Exodus, FlexiSpy, Mandrake, FluBot, S.O.V.A., and other mobile malware or surveillanceware entries; validate whether telemetry would show the relevant platform and device-integrity conditions.

Mitigation priorities

  • Use M1006 as a baseline priority: keep mobile operating systems on recent supported versions to benefit from patches and security architecture improvements.
  • Enforce mobile compliance policies that restrict rooted or jailbroken devices from business resources.
  • Review internally developed and high-risk third-party mobile apps for unsafe storage patterns, including unprotected external storage and insecure file permissions.
  • Apply mobile application management or device management controls to separate business data from unmanaged personal app data where feasible.
  • Prioritize executive, administrator, regulated-data, and incident-response user populations for stronger mobile posture enforcement and monitoring.
Additional notes and limits

The materiality of T1409 depends heavily on local mobile architecture: managed versus unmanaged devices, use of corporate apps, app storage practices, OS versions, and whether security tooling can observe root or jailbreak state. The large set of ATT&CK software relationships suggests this is a common objective or capability across mobile malware reporting, but those relationships should be used for defensive prioritization rather than assumptions about active exposure in a specific environment.

The ATT&CK object does not specify tactics and provides no official detection text. The supplied data supports Android and iOS scope, the three described enabling scenarios, one mitigation relationship, one detection-strategy relationship, and listed campaign/group/software relationships. It does not by itself prove active exploitation, customer exposure, successful data theft, or detection coverage in any environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Stored Application Data

Adversaries may try to access and collect application data resident on the device. Adversaries often target popular applications, such as Facebook, WeChat, and Gmail.[1]

Due to mobile OS sandboxing, this technique is only possible in three scenarios:

* An application stores files in unprotected external storage * An application stores files in its internal storage directory with insecure permissions (e.g. 777) * The adversary gains root permissions on the device

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupMobile

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

MalwareMobile

S1079: BOULDSPY

BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities. Analysis of exfiltrated C2 data suggests that BOULDSPY primarily targeted minority groups in Iran.[1]

Android
MalwareMobile

S0509: FakeSpy

FakeSpy is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.[1]

Android
MalwareMobile

S0405: Exodus

Exodus is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).[1]

Android
MalwareMobile

S0485: Mandrake

Mandrake is a sophisticated Android espionage platform that has been active in the wild since at least 2016. Mandrake is very actively maintained, with sophisticated features and attacks that are executed with surgical precision.

Mandrake has gone undetected for several years by providing legitimate, ad-free applications with social media and real reviews to back the apps. The malware is only activated when the operators issue a specific command.[1]

Android
ToolMobile

S0408: FlexiSpy

FlexiSpy is sophisticated surveillanceware for iOS and Android. Publicly-available, comprehensive analysis has only been found for the Android version.[1][2]

FlexiSpy markets itself as a parental control and employee monitoring application.[3]

Android
MalwareMobile

S1062: S.O.V.A.

S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of applications, including banking, cryptocurrency wallet/exchange, and shopping apps. S.O.V.A., which is Russian for "owl", contains features not commonly found in Android malware, such as session cookie theft.[1][2]

Android
MalwareMobile

S1067: FluBot

FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020. It primarily spread through European countries using a variety of SMS phishing messages in multiple languages.[1][2] An international law enforcement operation of 11 countries eventually disrupted the spread of FluBot.[3]

Android
MalwareMobile

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
MalwareMobile

S1128: HilalRAT

HilalRAT is a remote access-capable Android malware, developed and used by UNC788.[1] HilalRAT is capable of collecting data, such as device location, call logs, etc., and is capable of executing actions, such as activating a device's camera and microphone.[1]

Android
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.1
Created
Modified
Raw hash
9008e947ce5379f9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.13.1Current bundle9008e947ce53…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  2. [2]
    Lookout Dark Caracal Jan 2018

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

    Open source URL
  3. [3]
    lookout_bouldspy_0423

    Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.

    Open source URL
  4. [4]
    Cybereason FakeSpy

    O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020.

    Open source URL
  5. [5]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  6. [6]
    FortiGuard-FlexiSpy

    K. Lu. (n.d.). Deep Technical Analysis of the Spyware FlexiSpy for Android. Retrieved September 10, 2019.

    Open source URL
  7. [7]
    threatfabric_sova_0921

    ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023.

    Open source URL
  8. [8]
    cleafy_sova_1122

    Francesco Lubatti, Federico Valentini. (2022, November 8). SOVA malware is back and is evolving rapidly. Retrieved March 30, 2023.

    Open source URL
  9. [9]
    Lookout-PegasusAndroid

    Mike Murray. (2017, April 3). Pegasus for Android: the other side of the story emerges. Retrieved April 16, 2017.

    Open source URL
  10. [10]
    TrendMicro-RCSAndroid

    Veo Zhang. (2015, July 21). Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In. Retrieved December 22, 2016.

  11. [11]
    Europol FluBot Jun2022

    Europol. (2022, June 1). Takedown of SMS-based FluBot spyware infecting Android phones. Retrieved April 18, 2024.

    Open source URL
  12. [12]
    MelikovBlackBerry LightSpy 2024

    Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.

    Open source URL
  13. [13]
    Threatfabric LightSpy 2023

    ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.

    Open source URL
  14. [14]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  15. [15]
    Meta Adversarial Threat Report 2022

    Agranovich, D., et al. (2022, April). Adversarial Threat Report. Retrieved April 2, 2024.

    Open source URL
  16. [16]
    Trend Micro FlyTrap

    Trend Micro. (2021, August 17). FlyTrap Android Malware Is Taking Over Facebook Accounts — Protect Yourself With a Malware Scanner. Retrieved September 28, 2023.

    Open source URL
  17. [17]
    Zimperium FlyTrap

    A. Yaswant. (2021, August 9). FlyTrap Android Malware Compromises Thousands of Facebook Accounts. Retrieved September 28, 2023.

    Open source URL
  18. [18]
    paloalto_yispecter_1015

    Claud Xiao. (2015, October 4). YiSpecter: First iOS Malware That Attacks Non-jailbroken Apple iOS Devices by Abusing Private APIs. Retrieved March 3, 2023.

    Open source URL
  19. [19]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  20. [20]
    Lookout-StealthMango

    Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.

    Open source URL
  21. [21]
    Lookout Desert Scorpion

    A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.

    Open source URL
  22. [22]
    checkpoint_flixonline_0421

    Aviran Hazum, Bodgan Melnykov, Israel Wenik. (2021, April 7). New Wormable Android Malware Spreads by Creating Auto-Replies to Messages in WhatsApp. Retrieved January 26, 2024.

    Open source URL
  23. [23]
    Lookout-Pegasus

    Lookout. (2016). Technical Analysis of Pegasus Spyware. Retrieved December 12, 2016.

    Open source URL
  24. [24]
    Lookout_DCHSpy_July2025

    Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025.

    Open source URL
  25. [25]
    SecureList OpTriangulation 23Oct2023

    Kucherin, G., et al. (2023, October 23). The outstanding stealth of Operation Triangulation. Retrieved April 18, 2024.

    Open source URL
  26. [26]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  27. [27]
    Lookout FrozenCell

    Michael Flossman. (2017, October 5). FrozenCell: Multi-platform surveillance campaign against Palestinians. Retrieved November 11, 2020.

    Open source URL
  28. [28]
    PaloAlto-SpyDealer

    Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.

    Open source URL
  29. [29]
    mandiant_apt44_unearthing_sandworm

    Roncone, G. et al. (n.d.). APT44: Unearthing Sandworm. Retrieved July 11, 2024.

    Open source URL
  30. [30]
    ESET_VajraSpy_Feb2024

    Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.

    Open source URL
  31. [31]
    K7Dhanalakshmi_VajraSpy_April2022

    Dhanalakshmi. (2022, April 19). VajraSpy – An Android RAT. Retrieved November 5, 2025.

    Open source URL
  32. [32]
    Kaspersky-Skygofree

    Nikita Buchka and Alexey Firsh. (2018, January 16). Skygofree: Following in the footsteps of HackingTeam. Retrieved September 24, 2018.

    Open source URL
  33. [33]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  34. [34]
    SecureList BusyGasper

    Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021.

    Open source URL
  35. [35]
    NIST Mobile Threat CatalogueAUT-0
    Open source URL
  36. [36]
    NIST Mobile Threat CatalogueAUT-0
    Open source URL
  37. [37]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  38. [38]
    mitre-attackT1409
    Open source URL
  39. [39]
    mitre-attackT1409
    Open source URL
  40. [40]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  41. [41]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  42. [42]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  43. [43]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.