LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1437.001: Web Protocols

Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic. Commands to remote mobile devices, and often the results of those commands, will be embedded within the protocol traffic between the mobile client and server.

Web protocols such as HTTP and HTTPS are used for web traffic as well as well as notification services native to mobile messaging services such as Google Cloud Messaging (GCM) and newly, Firebase Cloud Messaging (FCM), (GCM/FCM: two-way communication) and Apple Push Notification Service (APNS; one-way server-to-device). Such notification services leverage HTTP/S via the respective API and are commonly abused on Android and iOS respectively in order blend in with routine device traffic making it difficult for enterprises to inspect.

MobileT1437.001Sub-techniqueObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Web Protocols for mobile ATT&CK describes adversary command-and-control or data exchange hidden inside normal-looking HTTP/HTTPS and mobile notification traffic. For leaders, the issue is not that web traffic exists; it is that Android and iOS devices routinely use encrypted web and push-notification services that enterprises may have limited ability to inspect, making mobile compromise harder to separate from legitimate business traffic.

Executive priority

Prioritize this where mobile devices handle sensitive communications, financial workflows, identity approval, or regulated data. The decision question is whether the organization can explain and evidence how it monitors managed mobile devices, risky apps, and unusual network destinations without relying on full content inspection. This technique is also relevant to IR readiness: if a mobile incident occurs, teams need mobile network, app, and device-management evidence available quickly enough to determine whether command traffic used common web or notification channels.

Technical view

This is a mobile sub-technique of Application Layer Protocol affecting Android and iOS. ATT&CK does not provide a detection description, but the relationship to DET0620 indicates a detection strategy exists. SOC and detection teams should validate visibility for mobile HTTP/HTTPS patterns, connections to unfamiliar client/server infrastructure, and abuse patterns around Google Cloud Messaging/Firebase Cloud Messaging on Android and Apple Push Notification Service on iOS. Because the related ATT&CK relationships include multiple Android malware families, iOS spyware, and a documented campaign/group using this behavior, detections should be tested against mobile-specific C2 assumptions rather than only desktop web-proxy logic.

Likely telemetry

  • Mobile device management or enterprise mobility management device and app inventory
  • Mobile threat defense or mobile endpoint security alerts, where deployed
  • Network, secure web gateway, proxy, firewall, or VPN metadata for mobile device traffic
  • DNS resolution logs associated with managed mobile devices
  • TLS/HTTPS metadata such as destination, certificate, SNI, timing, and volume where lawfully and technically available

Detection direction

  • Confirm whether managed Android and iOS traffic is attributable to a user, device, and installed app; lack of attribution is a major blind spot for this behavior.
  • Baseline expected mobile web and notification-service destinations, then investigate unusual domains, rare endpoints, abnormal beaconing cadence, or unexpected data volume from mobile apps.
  • Tune carefully: HTTP/HTTPS, FCM, GCM, and APNS are common legitimate services, so detection should rely on context, app reputation, device posture, destination rarity, and behavioral anomalies rather than protocol presence alone.
  • Correlate mobile network events with app inventory and recent app installs, especially for sideloaded, unmanaged, or policy-noncompliant apps.
  • Ensure incident responders can preserve relevant MDM/EMM, network, DNS, and mobile security logs before short retention windows expire.

Mitigation priorities

  • Establish mobile device enrollment, app inventory, and compliance baselines for devices accessing sensitive services.
  • Restrict unmanaged or high-risk apps where business policy allows, and review sideloading exposure on Android and enterprise/developer profile exposure on iOS.
  • Route managed mobile traffic through approved security controls where feasible, while recognizing encrypted web and notification traffic may limit content inspection.
  • Use risk-based conditional access so mobile device posture affects access to business applications and identity workflows.
  • Maintain IR playbooks for mobile compromise that include collection of device-management records, app lists, network metadata, and DNS/proxy evidence.
Additional notes and limits

ATT&CK links this technique to many mobile software entries, including Android malware, iOS spyware, and banking or spyware families, plus campaign/group context. That relationship breadth makes the behavior strategically important for mobile defense, but it does not by itself prove current activity in any environment. The strongest local validation will come from whether mobile traffic can be tied back to a device and app.

The official ATT&CK object has no tactic and no official detection text. Recommendations are therefore framed as validation directions based on the supplied description, platforms, external references, and relationships, not as guaranteed detections or vendor-specific controls.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Web Protocols

Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic. Commands to remote mobile devices, and often the results of those commands, will be embedded within the protocol traffic between the mobile client and server.

Web protocols such as HTTP and HTTPS are used for web traffic as well as well as notification services native to mobile messaging services such as Google Cloud Messaging (GCM) and newly, Firebase Cloud Messaging (FCM), (GCM/FCM: two-way communication) and Apple Push Notification Service (APNS; one-way server-to-device). Such notification services leverage HTTP/S via the respective API and are commonly abused on Android and iOS respectively in order blend in with routine device traffic making it difficult for enterprises to inspect.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
MobileT1437Application Layer ProtocolThis object subtechnique of Application Layer Protocol.
Associated objects

Groups, software, and campaigns

MalwareMobile

S1093: FlyTrap

FlyTrap is an Android trojan, first detected in March 2021, that uses social engineering tactics to compromise Facebook accounts. FlyTrap was initially detected through infected apps on the Google Play store, and is believed to have impacted over 10,000 victims across at least 140 countries.[1]

Android
MalwareMobile

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
MalwareMobile

S0478: EventBot

EventBot is an Android banking trojan and information stealer that abuses Android’s accessibility service to steal data from various applications.[1] EventBot was designed to target over 200 different banking and financial applications, the majority of which are European bank and cryptocurrency exchange applications.[1]

Android
MalwareMobile

S1241: RatMilad

RatMilad is an Android remote access tool (RAT) with spyware functionality that has been used to target enterprise mobile devices in the Middle East since at least 2021. Variants of RatMilad have been disguised as VPN applications and a fake app named NumRent. Upon installation, RatMilad employs multiple Collection techniques to collect sensitive information before uploading the collected data to its command and control (C2) server. [1]

Android
MalwareMobile

S1095: AhRat

AhRat is an Android remote access tool based on the open-source AhMyth remote access tool. AhRat initially spread in August 2022 on the Google Play Store via an update containing malicious code to the previously benign application, “iRecorder – Screen Recorder,” which itself was released in September 2021.[1]

Android
MalwareMobile

S0427: TrickMo

TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot. TrickMo has been primarily targeting users located in Germany.[1]

TrickMo is designed to steal transaction authorization numbers (TANs), which are typically used as one-time passwords.[1]

Android
MalwareMobile

S1083: Chameleon

Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities. Believed to have been first active in January 2023, Chameleon has been observed targeting users in Australia and Poland by masquerading as official applications. A new variant of Chameleon has expanded its targets to include Android users in the United Kingdom and Italy.[1][2]

Android
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
97a6e462ff7b77ea...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle97a6e462ff7b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Talos GPlayed

    V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020.

    Open source URL
  2. [2]
    welivesec_strongpity

    Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.

    Open source URL
  3. [3]
    Zimperium FlyTrap

    A. Yaswant. (2021, August 9). FlyTrap Android Malware Compromises Thousands of Facebook Accounts. Retrieved September 28, 2023.

    Open source URL
  4. [4]
    Threatfabric LightSpy 2023

    ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.

    Open source URL
  5. [5]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  6. [6]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  7. [7]
    Cybereason EventBot

    D. Frank, L. Rochberger, Y. Rimmer, A. Dahan. (2020, April 30). EventBot: A New Mobile Banking Trojan is Born. Retrieved June 26, 2020.

    Open source URL
  8. [8]
    ZimperiumGupta_RatMilad_Oct2022

    Gupta, N. (2022, October 5). We Smell A RatMilad Android Spyware. Retrieved August 27, 2025.

    Open source URL
  9. [9]
    welivesecurity_ahrat_0523

    Lukas Stefanko. (2023, May 23). Android app breaking bad: From legitimate screen recording to file exfiltration within a year. Retrieved December 18, 2023.

    Open source URL
  10. [10]
    CYBERWARCON CHEMISTGAMES

    B. Leonard, N. Mehta. (2019, November 21). The Secret Life of Sandworms. Retrieved December 31, 2020.

    Open source URL
  11. [11]
    SecurityIntelligence TrickMo

    P. Asinovsky. (2020, March 24). TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany. Retrieved April 24, 2020.

    Open source URL
  12. [12]
    Kaspersky-MobileMalware

    Roman Unuchek and Victor Chebyshev. (2014, February 24). Mobile Malware Evolution: 2013. Retrieved December 22, 2016.

    Open source URL
  13. [13]
    Kaspersky Riltok June 2019

    Tatyana Shishkova. (2019, June 25). Riltok mobile Trojan: A banker with global reach. Retrieved August 7, 2019.

    Open source URL
  14. [14]
    cyble_chameleon_0423

    Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023.

    Open source URL
  15. [15]
    Wandera-RedDrop

    Nell Campbell. (2018, February 27). RedDrop: the blackmailing mobile malware family lurking in app stores. Retrieved November 17, 2024.

    Open source URL
  16. [16]
    ZimperiumOrtegaPratapagiri_GodFather_Jun2025

    Ortega, F. Pratapagiri, V. (2025, June 18). Your Mobile App, Their Playground: The Dark Side of Virtualization. Retrieved July 16, 2025.

    Open source URL
  17. [17]
    Symantec GoldenCup

    R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020.

    Open source URL
  18. [18]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  19. [19]
    Kaspersky-WUC

    Costin Raiu, Denis Maslennikov, Kurt Baumgartner. (2013, March 26). Android Trojan Found in Targeted Attack. Retrieved December 23, 2016.

    Open source URL
  20. [20]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  21. [21]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  22. [22]
    FireEye-RuMMS

    Wu Zhou, Deyu Hu, Jimmy Su, Yong Kang. (2016, April 26). RUMMS: THE LATEST FAMILY OF ANDROID MALWARE ATTACKING USERS IN RUSSIA VIA SMS PHISHING. Retrieved February 6, 2017.

    Open source URL
  23. [23]
    WeLiveSecurity AdDisplayAshas

    L. Stefanko. (2019, October 24). Tracking down the developer of Android adware affecting millions of users. Retrieved October 29, 2020.

    Open source URL
  24. [24]
    lookout_abstractemu_1021

    P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.

    Open source URL
  25. [25]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  26. [26]
    Lookout Dark Caracal Jan 2018

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

    Open source URL
  27. [27]
    paloalto_yispecter_1015

    Claud Xiao. (2015, October 4). YiSpecter: First iOS Malware That Attacks Non-jailbroken Apple iOS Devices by Abusing Private APIs. Retrieved March 3, 2023.

    Open source URL
  28. [28]
    lookout_bouldspy_0423

    Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.

    Open source URL
  29. [29]
    Securelist Asacub

    T. Shishkova. (2018, August 28). The rise of mobile banker Asacub. Retrieved December 14, 2020.

    Open source URL
  30. [30]
    securelist rotexy 2018

    T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019.

    Open source URL
  31. [31]
    CheckPoint Cerberus

    A. Hazum, B. Melnykov, C. Efrati, D. Golubenko, I. Wernik, L. Kuperman, O. Mana. (2020, April 29). First seen in the wild – Malware uses Corporate MDM as attack vector. Retrieved June 26, 2020.

    Open source URL
  32. [32]
    Threat Fabric Exobot

    Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020.

    Open source URL
  33. [33]
    ThreatFabric_Crocodilus_March2025

    ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025.

    Open source URL
  34. [34]
    proofpoint_flubot_0421

    Crista Giering, F. Naves, Andrew Conway, Adam McNeil . (2021, April 27). FluBot Android Malware Spreading Rapidly Through Europe, May Hit U.S. Soon. Retrieved February 28, 2023.

    Open source URL
  35. [35]
    Google Bread

    A. Guertin, V. Kotov, Android Security & Privacy Team. (2020, January 9). PHA Family Highlights: Bread (and Friends) . Retrieved April 27, 2020.

    Open source URL
  36. [36]
    cleafy_brata_0122

    Federico Valentini, Francesco Lubatti. (2022, January 24). How BRATA is monitoring your bank account. Retrieved December 18, 2023.

    Open source URL
  37. [37]
    Talos Gustuff Apr 2019

    Vitor Ventura. (2019, April 9). Gustuff banking botnet targets Australia . Retrieved September 3, 2019.

    Open source URL
  38. [38]
    ESET DEFENSOR ID

    L. Stefanko. (2020, May 22). Insidious Android malware gives up all malicious features but one to gain stealth. Retrieved June 26, 2020.

    Open source URL
  39. [39]
    welivesecurity_apt-c-23

    Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.

    Open source URL
  40. [40]
    sophos_android_apt_spyware

    Kohli, P. (2021, November 23). Android APT spyware, targeting Middle East victims, enhances evasiveness. Retrieved November 17, 2024.

    Open source URL
  41. [41]
    Volexity Insomnia

    A. Case, D. Lassalle, M. Meltzer, S. Koessel, et al.. (2020, April 21). Evil Eye Threat Actor Resurfaces with iOS Exploit and Updated Implant. Retrieved June 2, 2020.

    Open source URL
  42. [42]
    Sophos Red Alert 2.0

    J. Chandraiah. (2018, July 23). Red Alert 2.0: Android Trojan targets security-seekers. Retrieved December 14, 2020.

    Open source URL
  43. [43]
    nccgroup_sharkbot_0322

    RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023.

    Open source URL
  44. [44]
    SecureList - ViceLeaker 2019

    GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.

    Open source URL
  45. [45]
    Bitdefender - Triout 2018

    L. Arsene, C. Ochinca. (2018, August 20). Triout – Spyware Framework for Android with Extensive Surveillance Capabilities. Retrieved January 21, 2020.

    Open source URL
  46. [46]
    threatfabric_sova_0921

    ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023.

    Open source URL
  47. [47]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  48. [48]
    TrendMicro_CherryBlos_July2023

    Trend Micro Research. (2023, July 28). Related CherryBlos and FakeTrade Android Malware Involved in Scam Campaigns. Retrieved March 28, 2025.

    Open source URL
  49. [49]
    Kaspersky-Skygofree

    Nikita Buchka and Alexey Firsh. (2018, January 16). Skygofree: Following in the footsteps of HackingTeam. Retrieved September 24, 2018.

    Open source URL
  50. [50]
    Cybereason FakeSpy

    O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020.

    Open source URL
  51. [51]
    NIST Mobile Threat CatalogueAPP-29
    Open source URL
  52. [52]
    NIST Mobile Threat CatalogueAPP-29
    Open source URL
  53. [53]
    mitre-attackT1437.001
    Open source URL
  54. [54]
    mitre-attackT1437.001
    Open source URL
  55. [55]
    Kaspersky-MobileMalware

    Roman Unuchek and Victor Chebyshev. (2014, February 24). Mobile Malware Evolution: 2013. Retrieved December 22, 2016.

    Open source URL
  56. [56]
    Kaspersky-MobileMalware

    Roman Unuchek and Victor Chebyshev. (2014, February 24). Mobile Malware Evolution: 2013. Retrieved December 22, 2016.

    Open source URL
  57. [57]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  58. [58]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.