LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1422.002: Wi-Fi Discovery

Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Discovery or Credential Access activity to support both ongoing and future campaigns.

MobileT1422.002Sub-techniqueObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Wi-Fi Discovery is a mobile behavior where a compromised Android or iOS device is used to look for saved or nearby Wi-Fi network information, including network names and potentially passwords. For leaders, the risk is not just the phone: Wi-Fi details can help an adversary understand office, home, travel, or operational environments and may support later discovery or credential access activity.

Executive priority

Prioritize this as part of mobile security, identity, and incident response readiness where mobile devices connect to corporate, executive, regulated, or operational networks. The ATT&CK relationships show this behavior appears across multiple Android and iOS mobile malware entries, so executives should ask whether the organization can inventory mobile OS posture, restrict risky app access, preserve mobile evidence during incidents, and demonstrate that Wi-Fi credentials are not an unmanaged path into sensitive environments.

Technical view

This is a sub-technique of System Network Configuration Discovery for Android and iOS. MITRE does not provide technique-specific detection text, but a related detection strategy, DET0709 Detection of Wi-Fi Discovery, is linked. SOC and IR teams should validate whether mobile telemetry can show apps or processes attempting to access Wi-Fi configuration, saved network identifiers, connection metadata, or credential-related stores, and whether that activity can be correlated with suspicious app behavior or known mobile malware investigations. Because tactics are not specified in the object, map detections locally to discovery and credential-access use cases based on observed evidence rather than assuming intent.

Likely telemetry

  • Mobile device management or enterprise mobility management inventory for Android and iOS devices
  • Mobile OS version and patch-level data
  • Mobile app inventory, installation source, and permission posture
  • Mobile threat defense or endpoint telemetry for suspicious app behavior
  • Wi-Fi configuration and connection metadata where legally and technically available

Detection direction

  • Review DET0709, the linked detection strategy, and determine whether current mobile telemetry can observe Wi-Fi discovery attempts on Android and iOS.
  • Tune for suspicious access to Wi-Fi network information by apps that do not have a clear business need, especially when paired with spyware, banking trojan, or surveillanceware-like behavior identified in investigations.
  • Correlate mobile Wi-Fi discovery indicators with app installation source, unusual permissions, OS version, and other system network configuration discovery evidence.
  • Account for privacy and platform visibility limits: iOS and Android may restrict what defenders can collect, and BYOD programs may further limit monitoring.
  • Avoid treating all Wi-Fi metadata access as malicious; legitimate system services and enterprise network tools may generate benign activity.

Mitigation priorities

  • Maintain recent Android and iOS versions, aligning with MITRE mitigation M1006 Use Recent OS Version.
  • Use mobile device management controls to enforce OS update posture where appropriate.
  • Reduce exposure from untrusted or unnecessary mobile applications through approved app controls and user education consistent with the organization’s mobile policy.
  • Protect corporate Wi-Fi credentials with lifecycle management, segmentation, and rapid rotation procedures when mobile compromise is suspected.
  • Include mobile device evidence handling in incident response playbooks so Wi-Fi credential exposure can be assessed during containment.
Additional notes and limits

The relationship set links this technique to multiple mobile malware software objects, including Pegasus for Android, RedDrop, Monokle, Corona Updates, TrickMo, INSOMNIA, TianySpy, Hornbill, BOULDSPY, LightSpy, DocSwap, and VajraSpy. That supports treating Wi-Fi Discovery as a recurring mobile malware capability, but it does not by itself establish current exposure or active exploitation in any environment.

MITRE provides no official detection text and no tactics are specified in the supplied object fields. Practical coverage depends on local mobile management architecture, privacy constraints, platform restrictions, app telemetry, and incident response access to devices. The supplied fields support Android and iOS only for this technique.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Wi-Fi Discovery

Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Discovery or Credential Access activity to support both ongoing and future campaigns.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
MobileT1422System Network Configuration DiscoveryThis object subtechnique of System Network Configuration Discovery.
Associated objects

Groups, software, and campaigns

MalwareMobile

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
MalwareMobile

S1079: BOULDSPY

BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities. Analysis of exfiltrated C2 data suggests that BOULDSPY primarily targeted minority groups in Iran.[1]

Android
MalwareMobile

S0427: TrickMo

TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot. TrickMo has been primarily targeting users located in Germany.[1]

TrickMo is designed to steal transaction authorization numbers (TANs), which are typically used as one-time passwords.[1]

Android
MalwareMobile

S9005: DocSwap

DocSwap is an Android malware first identified in 2025, and attributed to Kimsuky. DocSwap’s name is a combination of its Korean name “문서열람 인증 앱” (Document Viewing Authentication App) and a phishing page masquerading as CoinSwap at the C2 address. Based on DocSwap’s name and Korean-language strings, DocSwap potentially targets mobile device users in South Korea. Several variants of DocSwap exist; one of the latest samples indicates that the adversary added a native decryption function that decrypts an internal APK.[1][2]

Android
MalwareMobile

S9006: VajraSpy

VajraSpy is Android malware distributed via trojanized messaging and news applications. It has been used to target individuals in Pakistan and India since at least 2021 and has been delivered through the Google Play Store, malicious domains, and other uncontrolled distribution channels. VajraSpy is attributed with high confidence to Patchwork which has used the malware to conduct targeted espionage, primarily against devices in Pakistan.[1][2][3]

Android
MalwareMobile

S0425: Corona Updates

Corona Updates is Android spyware that took advantage of the Coronavirus pandemic. The campaign distributing this spyware is tracked as Project Spy. Multiple variants of this spyware have been discovered to have been hosted on the Google Play Store.[1]

Android
MalwareMobile

S0407: Monokle

Monokle is targeted, sophisticated mobile surveillanceware. It is developed for Android, but there are some code artifacts that suggests an iOS version may be in development.[1]

Android
MalwareMobile

S1056: TianySpy

TianySpy is a mobile malware primarily spread by SMS phishing between September 30 and October 12, 2021. TianySpy is believed to have targeted credentials associated with membership websites of major Japanese telecommunication services.[1]

AndroidiOS
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
d000d12b092fe546...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundled000d12b092f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    MelikovBlackBerry LightSpy 2024

    Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.

    Open source URL
  2. [2]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  3. [3]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  4. [4]
    Threatfabric LightSpy 2023

    ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.

    Open source URL
  5. [5]
    lookout_bouldspy_0423

    Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.

    Open source URL
  6. [6]
    SecurityIntelligence TrickMo

    P. Asinovsky. (2020, March 24). TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany. Retrieved April 24, 2020.

    Open source URL
  7. [7]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  8. [8]
    Google Project Zero Insomnia

    I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020.

    Open source URL
  9. [9]
    ESET_VajraSpy_Feb2024

    Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.

    Open source URL
  10. [10]
    TelephonyManager

    Android. (n.d.). TelephonyManager. Retrieved December 21, 2016.

    Open source URL
  11. [11]
    Lookout-PegasusAndroid

    Mike Murray. (2017, April 3). Pegasus for Android: the other side of the story emerges. Retrieved April 16, 2017.

    Open source URL
  12. [12]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  13. [13]
    Lookout-Monokle

    Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019.

    Open source URL
  14. [14]
    Wandera-RedDrop

    Nell Campbell. (2018, February 27). RedDrop: the blackmailing mobile malware family lurking in app stores. Retrieved November 17, 2024.

    Open source URL
  15. [15]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  16. [16]
    trendmicro_tianyspy_0122

    Trend Micro. (2022, January 25). TianySpy Malware Uses Smishing Disguised as Message From Telco. Retrieved January 11, 2023.

    Open source URL
  17. [17]
    mitre-attackT1422.002
    Open source URL
  18. [18]
    mitre-attackT1422.002
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.