T1430: Location Tracking
Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
On Android, applications holding the `ACCESS_COAURSE_LOCATION` or `ACCESS_FINE_LOCATION` permissions provide access to the device’s physical location. On Android 10 and up, declaration of the `ACCESS_BACKGROUND_LOCATION` permission in an application’s manifest will allow applications to request location access even when the application is running in the background.[1] Some adversaries have utilized integration of Baidu map services to retrieve geographical location once the location access permissions had been obtained.[2][3]
On iOS, applications must include the `NSLocationWhenInUseUsageDescription`, `NSLocationAlwaysAndWhenInUseUsageDescription`, and/or `NSLocationAlwaysUsageDescription` keys in their `Info.plist` file depending on the extent of requested access to location information.[4] On iOS 8.0 and up, applications call `requestWhenInUseAuthorization()` to request access to location information when the application is in use or `requestAlwaysAuthorization()` to request access to location information regardless of whether the application is in use. With elevated privileges, an adversary may be able to access location data without explicit user consent with the `com.apple.locationd.preauthorized` entitlement key.[5]
Security context for executives and security teams
Location Tracking matters because a compromised or malicious mobile app can turn an employee’s Android or iOS device into a source of physical-location intelligence. For executives and security leaders, the risk is not only privacy; it can affect executive protection, field operations, critical infrastructure staff, investigations, and any business process where knowing a person’s location creates safety or operational risk.
Executive priority
Prioritize this where mobile devices are used by executives, administrators, responders, field personnel, government-facing staff, or operational teams. Leaders should ask whether the organization can prove which apps have location permissions, whether background location access is controlled, whether mobile OS versions are current, and whether EMM/MDM and cloud device-location services are governed and audited. This technique also supports compliance and privacy evidence because location data is sensitive and access should be justified, minimized, and monitored.
Technical view
For Android and iOS, validate controls around application permission requests and privileged access to location services. Android review should include apps requesting ACCESS_COAURSE_LOCATION, ACCESS_FINE_LOCATION, and ACCESS_BACKGROUND_LOCATION. iOS review should include Info.plist location usage keys, calls requesting when-in-use or always authorization, and unusual elevated entitlement use such as com.apple.locationd.preauthorized where observable. Because ATT&CK lists related sub-techniques for remote device management services and SS7 node impersonation, defenders should separate app-based location access from EMM/cloud-console tracking and telecom signaling exposure when scoping detections and response.
Likely telemetry
- Mobile device inventory with OS version for Android and iOS
- Mobile application inventory and app provenance
- Android application manifest permissions, including foreground and background location permissions
- iOS application Info.plist location usage keys and relevant entitlements where available
- MDM/EMM policy state, compliance posture, and device-location feature configuration
Detection direction
- Use DET0675 as the ATT&CK-linked detection strategy reference, but validate locally because the official technique object does not provide detection text.
- Tune for unjustified or high-risk location access: apps requesting always-on or background location, apps with location permissions outside business need, and newly installed or sideloaded apps requesting location data.
- Correlate permission findings with app reputation, installation source, device risk state, OS version, and network activity to reduce false positives from legitimate navigation, logistics, safety, or device-management use cases.
- For iOS, review location usage declarations and elevated entitlement indicators where tooling can expose them; absence of visibility into iOS internals is a common blind spot.
- For Android, ensure app manifest and runtime permission state are both assessed; manifest-only review may miss whether users granted access, while runtime-only review may miss latent capability.
Mitigation priorities
- Keep mobile devices on recent Android and iOS versions, aligning with M1006, because newer OS versions add patches and security architecture improvements.
- Use enterprise policy through EMM/MDM, aligning with M1012, to restrict risky app sources, govern location permissions, and enforce mobile compliance requirements where supported.
- Provide user guidance, aligning with M1011, so users understand location prompts, background access requests, and risky app installation behavior.
- Review and limit use of device-location features in EMM/MDM and cloud services to authorized roles with auditability.
- Apply app vetting and privacy review before approving business apps that request location access, especially always-on or background location.
Additional notes and limits
ATT&CK associates this technique with Android and iOS and with multiple campaigns, groups, and software entries, including mobile spyware and Android/iOS malware families. Those relationships show the behavior is observed across mobile threat reporting, but they do not by themselves prove current targeting of any specific organization. The parent technique covers app/API-based location access, while its sub-techniques expand the defensive scope to remote device-management services and SS7 impersonation.
The supplied ATT&CK object has no official detection text and no specified tactic. Detection recommendations therefore depend on local mobile-management visibility, app-vetting capability, OS telemetry, and audit logging. Some evidence, especially iOS entitlements or telecom signaling data, may not be available to a typical enterprise SOC without specialized tooling or provider cooperation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Location Tracking
Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
On Android, applications holding the `ACCESS_COAURSE_LOCATION` or `ACCESS_FINE_LOCATION` permissions provide access to the device’s physical location. On Android 10 and up, declaration of the `ACCESS_BACKGROUND_LOCATION` permission in an application’s manifest will allow applications to request location access even when the application is running in the background.[1] Some adversaries have utilized integration of Baidu map services to retrieve geographical location once the location access permissions had been obtained.[2][3]
On iOS, applications must include the `NSLocationWhenInUseUsageDescription`, `NSLocationAlwaysAndWhenInUseUsageDescription`, and/or `NSLocationAlwaysUsageDescription` keys in their `Info.plist` file depending on the extent of requested access to location information.[4] On iOS 8.0 and up, applications call `requestWhenInUseAuthorization()` to request access to location information when the application is in use or `requestAlwaysAuthorization()` to request access to location information regardless of whether the application is in use. With elevated privileges, an adversary may be able to access location data without explicit user consent with the `com.apple.locationd.preauthorized` entitlement key.[5]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Related techniques
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Mobile | T1430.001 | Remote Device Management ServicesSub-technique | Remote Device Management Services subtechnique of this object. |
| Mobile | T1430.002 | Impersonate SS7 NodesSub-technique | Impersonate SS7 Nodes subtechnique of this object. |
Groups, software, and campaigns
G0112: Windshift
S0577: FrozenCell
FrozenCell is the mobile component of a family of surveillanceware, with a corresponding desktop component known as KasperAgent and Micropsia.[1]
There are multiple close variants of FrozenCell, such as VAMP[2], GnatSpy[3], Desert Scorpion and SpyC23, which add some additional functionality but are not significantly different from the original malware.
S0463: INSOMNIA
S0305: SpyNote RAT
SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps. The SpyNote RAT builder tool can be used to develop malicious apps with the malware's functionality. [1]
S1094: BRATA
BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks. There are currently three known variants of BRATA.[1][2][3]
S0558: Tiktok Pro
Tiktok Pro is spyware that has been masquerading as the TikTok application.[1]
S0291: PJApps
S1069: TangleBot
TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada. TangleBot has used SMS text message lures about COVID-19 regulations and vaccines to trick mobile users into downloading the malware, similar to FluBot Android malware campaigns.[1]
S0327: Skygofree
S1083: Chameleon
Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities. Believed to have been first active in January 2023, Chameleon has been observed targeting users in Australia and Poland by masquerading as official applications. A new variant of Chameleon has expanded its targets to include Android users in the United Kingdom and Italy.[1][2]
S1216: TriangleDB
TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation Triangulation’s infection chain. Upon execution, TriangleDB communicates with the C2 server, relaying information about the victim device.[1]
S0555: CHEMISTGAMES
CHEMISTGAMES is a modular backdoor that has been deployed by Sandworm Team.[1]
S0425: Corona Updates
Corona Updates is Android spyware that took advantage of the Coronavirus pandemic. The campaign distributing this spyware is tracked as Project Spy. Multiple variants of this spyware have been discovered to have been hosted on the Google Play Store.[1]
C0054: Operation Triangulation
Operation Triangulation is a mobile campaign targeting iOS devices.[1] The unidentified actors used zero-click exploits in iMessage attachments to gain Initial Access, then executed exploits and validators, such as Binary Validator before finally executing the TriangleDB implant.
C0033: C0033
C0033 was a PROMETHIUM campaign during which they used StrongPity to target Android users. C0033 was the first publicly documented mobile campaign for PROMETHIUM, who previously used Windows-based techniques.[1]
All related ATT&CK context
Mitigation direction
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.2 | Current bundle | 8bf08e700ecf… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Android Request Location Permissions
Android Developers. (2022, March 24). Request Location Permissions. Retrieved April 1, 2022.
Open source URL - [2]PaloAlto-SpyDealer
Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.
Open source URL - [3]Palo Alto HenBox
A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.
Open source URL - [4]Apple Requesting Authorization for Location Services
Apple Developers. (n.d.). Requesting Authorization for Location Services. Retrieved April 1, 2022.
Open source URL - [5]Google Project Zero Insomnia
I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020.
Open source URL - [6]Lookout FrozenCell
Michael Flossman. (2017, October 5). FrozenCell: Multi-platform surveillance campaign against Palestinians. Retrieved November 11, 2020.
Open source URL - [7]Zscaler-SpyNote
Shivang Desai. (2017, January 23). SpyNote RAT posing as Netflix app. Retrieved January 26, 2017.
Open source URL - [8]cleafy_brata_0122
Federico Valentini, Francesco Lubatti. (2022, January 24). How BRATA is monitoring your bank account. Retrieved December 18, 2023.
Open source URL - [9]Zscaler TikTok Spyware
S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021.
Open source URL - [10]Lookout-EnterpriseApps
Lookout. (2016, May 25). 5 active mobile threats spoofing enterprise apps. Retrieved December 19, 2016.
Open source URL - [11]cloudmark_tanglebot_0921
Felipe Naves, Andrew Conway, W. Stuart Jones, Adam McNeil . (2021, September 23). TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures. Retrieved February 28, 2023.
Open source URL - [12]SecureList OpTriangulation 21Jun2023
Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.
Open source URL - [13]SecureList OpTriangulation 23Oct2023
Kucherin, G., et al. (2023, October 23). The outstanding stealth of Operation Triangulation. Retrieved April 18, 2024.
Open source URL - [14]Kaspersky-Skygofree
Nikita Buchka and Alexey Firsh. (2018, January 16). Skygofree: Following in the footsteps of HackingTeam. Retrieved September 24, 2018.
Open source URL - [15]cyble_chameleon_0423
Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023.
Open source URL - [16]CYBERWARCON CHEMISTGAMES
B. Leonard, N. Mehta. (2019, November 21). The Secret Life of Sandworms. Retrieved December 31, 2020.
Open source URL - [17]TrendMicro Coronavirus Updates
T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.
Open source URL - [18]kaspersky_fakecalls_0422
Igor Golovin. (2022, April 11). Fakecalls: a talking Trojan. Retrieved July 21, 2023.
Open source URL - [19]Trend Micro Bouncing Golf 2019
E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020.
Open source URL - [20]Bleeipng Computer Escobar
B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.
Open source URL - [21]Lookout_DCHSpy_July2025
Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025.
Open source URL - [22]welivesecurity_ahrat_0523
Lukas Stefanko. (2023, May 23). Android app breaking bad: From legitimate screen recording to file exfiltration within a year. Retrieved December 18, 2023.
Open source URL - [23]ESET_VajraSpy_Feb2024
Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.
Open source URL - [24]K7Dhanalakshmi_VajraSpy_April2022
Dhanalakshmi. (2022, April 19). VajraSpy – An Android RAT. Retrieved November 5, 2025.
Open source URL - [25]SentinelLabs AridViper 2023
Delamotte, A. (2023, November 6). Arid Viper | APT’s Nest of SpyC23 Malware Continues to Target Android Devices. Retrieved December 2, 2024.
Open source URL - [26]Lookout Uyghur Campaign
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.
Open source URL - [27]lookout_hornbill_sunbird_0221
Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.
Open source URL - [28]Threat Fabric Cerberus
Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020.
Open source URL - [29]Lookout eSurv
A. Bauer. (2019, April 8). Lookout discovers phishing sites distributing new iOS and Android surveillanceware. Retrieved September 11, 2020.
Open source URL - [30]Lookout-StealthMango
Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.
Open source URL - [31]Lookout ViperRAT
M. Flossman. (2017, February 16). ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar. Retrieved September 11, 2020.
Open source URL - [32]Cofense Anubis
M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024.
Open source URL - [33]CheckPoint-Charger
Oren Koriat and Andrey Polkovnichenko. (2017, January 24). Charger Malware Calls and Raises the Risk on Google Play. Retrieved January 24, 2017.
- [34]Symantec GoldenCup
R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020.
Open source URL - [35]ZimperiumGupta_RatMilad_Oct2022
Gupta, N. (2022, October 5). We Smell A RatMilad Android Spyware. Retrieved August 27, 2025.
Open source URL - [36]NYTimes-BackDoor
Matt Apuzzo and Michael S. Schmidt. (2016, November 15). Secret Back Door in Some U.S. Phones Sent Data to China, Analysts Say. Retrieved February 6, 2017.
Open source URL - [37]Trend Micro FlyTrap
Trend Micro. (2021, August 17). FlyTrap Android Malware Is Taking Over Facebook Accounts — Protect Yourself With a Malware Scanner. Retrieved September 28, 2023.
Open source URL - [38]Meta Adversarial Threat Report 2022
Agranovich, D., et al. (2022, April). Adversarial Threat Report. Retrieved April 2, 2024.
Open source URL - [39]Lookout-Pegasus
Lookout. (2016). Technical Analysis of Pegasus Spyware. Retrieved December 12, 2016.
Open source URL - [40]Lookout Desert Scorpion
A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.
Open source URL - [41]Kaspersky-WUC
Costin Raiu, Denis Maslennikov, Kurt Baumgartner. (2013, March 26). Android Trojan Found in Targeted Attack. Retrieved December 23, 2016.
Open source URL - [42]CrowdStrike-Android
CrowdStrike Global Intelligence Team. (2016). Use of Fancy Bear Android Malware in Tracking of Ukrainian FIeld Artillery Units. Retrieved February 6, 2017.
Open source URL - [43]SecureList - ViceLeaker 2019
GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.
Open source URL - [44]Bitdefender - Triout 2018
L. Arsene, C. Ochinca. (2018, August 20). Triout – Spyware Framework for Android with Extensive Surveillance Capabilities. Retrieved January 21, 2020.
Open source URL - [45]Lookout Dark Caracal Jan 2018
Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
Open source URL - [46]CSRIC5-WG10-FinalReport
Communications Security, Reliability, Interoperability Council (CSRIC). (2017, March). Working Group 10 Legacy Systems Risk Reductions Final Report. Retrieved May 24, 2017.
Open source URL - [47]SecureList BusyGasper
Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021.
Open source URL - [48]BlackBerry Bahamut
The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.
Open source URL - [49]EnkiWhiteHat_KimsukyDOCSWAP_Dec2025
EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.
Open source URL - [50]S2W_DocSwap_Mar2025
Kim, H., S2W TALON. (2025, March 13). Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer. Retrieved January 12, 2026.
Open source URL - [51]Bitdefender Mandrake
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.
Open source URL - [52]MelikovBlackBerry LightSpy 2024
Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.
Open source URL - [53]Threatfabric LightSpy 2023
ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.
Open source URL - [54]Shoshin_Kaspersky LightSpy 2020
Shoshin, P. (2020, March 27). LightSpy spyware targets iPhone users in Hong Kong. Retrieved February 12, 2025.
Open source URL - [55]LinkedIn Dmitry LightSpy 2025
Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.
Open source URL - [56]Lookout-Monokle
Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019.
Open source URL - [57]lookout_abstractemu_1021
P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.
Open source URL - [58]SWB Exodus March 2019
Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.
Open source URL - [59]TrendMicro-RCSAndroid
Veo Zhang. (2015, July 21). Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In. Retrieved December 22, 2016.
- [60]CyberMerchants-FlexiSpy
Actis B. (2017, April 22). FlexSpy Application Analysis. Retrieved September 4, 2019.
- [61]welivesec_strongpity
Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.
Open source URL - [62]Talos GPlayed
V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020.
Open source URL - [63]lookout_bouldspy_0423
Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.
Open source URL - [64]Android Request Location Permissions
Android Developers. (2022, March 24). Request Location Permissions. Retrieved April 1, 2022.
Open source URL - [65]Apple Requesting Authorization for Location Services
Apple Developers. (n.d.). Requesting Authorization for Location Services. Retrieved April 1, 2022.
Open source URL - [66]Google Project Zero Insomnia
I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020.
Open source URL - [67]NIST Mobile Threat CatalogueAPP-24Open source URL
- [68]NIST Mobile Threat CatalogueAPP-24Open source URL
- [69]Palo Alto HenBox
A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.
Open source URL - [70]PaloAlto-SpyDealer
Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.
Open source URL - [71]mitre-attackT1430Open source URL
- [72]mitre-attackT1430Open source URL
- [73]Google Project Zero Insomnia
I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020.
Open source URL - [74]SecureList OpTriangulation 21Jun2023
Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.
Open source URL - [75]lookout_hornbill_sunbird_0221
Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.
Open source URL - [76]Lookout Uyghur Campaign
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.
Open source URL - [77]Lookout Dark Caracal Jan 2018
Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
Open source URL - [78]PaloAlto-SpyDealer
Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.
Open source URL - [79]Palo Alto HenBox
A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.
Open source URL - [80]Lookout Uyghur Campaign
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.
Open source URL - [81]Lookout-StealthMango
Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.
Open source URL - [82]Lookout-EnterpriseApps
Lookout. (2016, May 25). 5 active mobile threats spoofing enterprise apps. Retrieved December 19, 2016.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
