T1512: Video Capture
MITRE ATT&CK T1512: Video Capture Technique details for Android, iOS, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
Video Capture is a mobile technique where malware or scripts use a device camera to record video or capture images. For leaders, the business issue is not just data theft; it is surveillance risk from corporate or personally used mobile devices that may expose meetings, facilities, documents, personnel, or sensitive environments. ATT&CK lists both Android and iOS as relevant platforms, with normal camera access gated by user-granted permissions, while rooted or jailbroken devices may weaken those protections.
Executive priority
Prioritize this behavior where mobile devices are used in executive settings, regulated operations, critical infrastructure, government-facing work, or locations where physical visibility creates security risk. Key leadership questions: which apps are allowed camera access, how quickly can the organization identify suspicious camera permission use, are mobile OS versions kept current, and are rooted or jailbroken devices restricted from sensitive work? This technique also matters for audit and incident response because permission governance, mobile device posture, and app inventory can become the evidence that proves whether the organization had reasonable mobile surveillance controls.
Technical view
For SOC, detection engineering, and IR teams, validate mobile coverage for Android and iOS camera access indicators rather than relying on network telemetry alone. On Android, review applications requesting or holding android.permission.CAMERA. On iOS, review apps declaring NSCameraUsageDescription in Info.plist and correlate with user-granted camera permission. Investigations should distinguish expected camera use by approved business apps from unusual camera access by apps with remote access, spyware, or sideloaded characteristics. Relationship context shows many Android malware and spyware families use this technique, plus an iOS spyware example, so mobile app inventory, permission state, device integrity, and file/exfiltration follow-on evidence are important pivots. Official ATT&CK detection text is not provided, but a related detection strategy, DET0695 Detection of Video Capture, is supplied.
Likely telemetry
- Mobile device management or enterprise mobility inventory for installed apps and OS versions
- Android application permission data, especially android.permission.CAMERA
- iOS application metadata including NSCameraUsageDescription in Info.plist where available
- User-granted camera permission state for mobile apps
- Root or jailbreak posture and device compliance status
Detection direction
- Confirm whether mobile telemetry can show which apps request and are granted camera access on Android and iOS.
- Baseline approved business use of camera permissions to reduce false positives from conferencing, scanning, authentication, and field-work applications.
- Prioritize alerts where camera permission appears on apps that are unapproved, newly installed, sideloaded, associated with remote access behavior, or present on rooted or jailbroken devices.
- Correlate permission findings with device integrity, unusual media file creation, and outbound transfer activity rather than treating permission presence alone as proof of capture.
- Use relationship context to enrich hunting for Android spyware and RAT behaviors, while avoiding attribution claims unless local evidence supports them.
Mitigation priorities
- Keep mobile operating systems on recent supported versions, consistent with ATT&CK mitigation M1006 Use Recent OS Version.
- Enforce mobile device compliance rules that identify or restrict rooted and jailbroken devices, especially for sensitive roles and locations.
- Review and minimize camera permissions for enterprise-approved apps; remove or deny apps that do not have a business need for camera access.
- Maintain an authoritative mobile app inventory and approval process for Android and iOS devices used for business.
- Include mobile camera-permission review in incident response playbooks for suspected surveillanceware or mobile compromise.
Additional notes and limits
This object is especially relevant to mobile surveillance scenarios. The relationship set includes Windshift and numerous mobile software entries, mostly Android, that use Video Capture, supporting prioritization for mobile threat hunting and spyware response. However, those relationships should be used for context and enrichment, not as evidence that any specific organization is targeted or compromised.
The supplied ATT&CK object has no specified tactics and no official detection text. DET0695 is listed only as a related detection strategy without details. Local telemetry availability will determine whether teams can validate actual video capture versus only camera permission or app capability. Claims about impact, attribution, active exploitation, or confirmed detection coverage require organization-specific evidence beyond the supplied fields.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Video Capture
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Groups, software, and campaigns
G0112: Windshift
S0328: Stealth Mango
Stealth Mango is Android malware that has reportedly been used to successfully compromise the mobile devices of government officials, members of the military, medical professionals, and civilians. The iOS malware known as Tangelo is believed to be from the same developer. [1]
S0421: GolfSpy
GolfSpy is Android spyware deployed by the group Bouncing Golf.[1]
S9004: Crocodilus
Crocodilus is an Android banking Trojan that was discovered in March 2025. Crocodilus targeted users worldwide, including Turkey, Poland, Argentina, Brazil, Spain, the United States, Indonesia and India. Crocodilus has been customized based on the target location. For example, Crocodilus mimicked major Turkish and Spanish banks for users in Turkey and Spain, while users in Poland saw Facebook advertisements that promoted Crocodilus to claim bonus points.[1][2]
S1195: SpyC23
SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017. SpyC23 has been observed primarily targeting Android devices in the Middle East.[1]
There are multiple close variants of SpyC23, such as VAMP[2], GnatSpy[3], Desert Scorpion and FrozenCell, which add some additional functionality but are not significantly different from the original malware.
S1069: TangleBot
TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada. TangleBot has used SMS text message lures about COVID-19 regulations and vaccines to trick mobile users into downloading the malware, similar to FluBot Android malware campaigns.[1]
S0407: Monokle
S1092: Escobar
S1080: Fakecalls
S1243: DCHSpy
DCHSpy is an Android spyware likely used by MuddyWater. DCHSpy uses political decoys and masquerades as legitimate applications, such as VPNs and banking applications, to trick victims into downloading the malware. Once downloaded, DCHSpy collects information from the device and exfiltrates the data to the command and control (C2) server.[1]
S0489: WolfRAT
S0535: Golden Cup
Golden Cup is Android spyware that has been used to target World Cup fans.[1]
S0327: Skygofree
All related ATT&CK context
Mitigation direction
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 2.1 | Current bundle | 2b7fa939f33b… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Lookout-StealthMango
Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.
Open source URL - [2]Trend Micro Bouncing Golf 2019
E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020.
Open source URL - [3]ThreatFabric_Crocodilus_March2025
ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025.
Open source URL - [4]welivesecurity_apt-c-23
Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.
Open source URL - [5]sophos_android_apt_spyware
Kohli, P. (2021, November 23). Android APT spyware, targeting Middle East victims, enhances evasiveness. Retrieved November 17, 2024.
Open source URL - [6]threatpost AndroidSpyware 2020
O'Donnell, L. (2020, September 30). Android Spyware Variant Snoops on WhatsApp, Telegram Messages. Retrieved January 10, 2025.
Open source URL - [7]cloudmark_tanglebot_0921
Felipe Naves, Andrew Conway, W. Stuart Jones, Adam McNeil . (2021, September 23). TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures. Retrieved February 28, 2023.
Open source URL - [8]Lookout-Monokle
Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019.
Open source URL - [9]Bleeipng Computer Escobar
B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.
Open source URL - [10]kaspersky_fakecalls_0422
Igor Golovin. (2022, April 11). Fakecalls: a talking Trojan. Retrieved July 21, 2023.
Open source URL - [11]Lookout_DCHSpy_July2025
Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025.
Open source URL - [12]Talos-WolfRAT
W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back... . Retrieved July 20, 2020.
Open source URL - [13]Symantec GoldenCup
R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020.
Open source URL - [14]Android Capture Sensor 2019
Android Developers. (, January). Android 9+ Privacy Changes . Retrieved August 27, 2019.
Open source URL - [15]BlackBerry Bahamut
The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.
Open source URL - [16]Kaspersky-Skygofree
Nikita Buchka and Alexey Firsh. (2018, January 16). Skygofree: Following in the footsteps of HackingTeam. Retrieved September 24, 2018.
Open source URL - [17]Lookout ViperRAT
M. Flossman. (2017, February 16). ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar. Retrieved September 11, 2020.
Open source URL - [18]SWB Exodus March 2019
Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.
Open source URL - [19]EnkiWhiteHat_KimsukyDOCSWAP_Dec2025
EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.
Open source URL - [20]S2W_DocSwap_Mar2025
Kim, H., S2W TALON. (2025, March 13). Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer. Retrieved January 12, 2026.
Open source URL - [21]Zscaler-SuperMarioRun
Viral Gandhi. (2017, January 12). Super Mario Run Malware #2 – DroidJack RAT. Retrieved January 20, 2017.
Open source URL - [22]forcepoint_bitter
Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved March 1, 2024.
Open source URL - [23]TrendMicro Coronavirus Updates
T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.
Open source URL - [24]Lookout Uyghur Campaign
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.
Open source URL - [25]Lookout Desert Scorpion
A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.
Open source URL - [26]SecureList BusyGasper
Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021.
Open source URL - [27]Meta Adversarial Threat Report 2022
Agranovich, D., et al. (2022, April). Adversarial Threat Report. Retrieved April 2, 2024.
Open source URL - [28]lookout_abstractemu_1021
P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.
Open source URL - [29]ESET_VajraSpy_Feb2024
Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.
Open source URL - [30]K7Dhanalakshmi_VajraSpy_April2022
Dhanalakshmi. (2022, April 19). VajraSpy – An Android RAT. Retrieved November 5, 2025.
Open source URL - [31]Palo Alto HenBox
A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.
Open source URL - [32]ZimperiumGupta_RatMilad_Oct2022
Gupta, N. (2022, October 5). We Smell A RatMilad Android Spyware. Retrieved August 27, 2025.
Open source URL - [33]CyberMerchants-FlexiSpy
Actis B. (2017, April 22). FlexSpy Application Analysis. Retrieved September 4, 2019.
- [34]Lookout-PegasusAndroid
Mike Murray. (2017, April 3). Pegasus for Android: the other side of the story emerges. Retrieved April 16, 2017.
Open source URL - [35]lookout_bouldspy_0423
Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.
Open source URL - [36]SecureList - ViceLeaker 2019
GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.
Open source URL - [37]TrendMicro-RCSAndroid
Veo Zhang. (2015, July 21). Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In. Retrieved December 22, 2016.
- [38]fb_arid_viper
Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.
Open source URL - [39]lookout_hornbill_sunbird_0221
Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.
Open source URL - [40]FirshSecureList LightSpy 2020
Firsh, A., et al. (2020, March 26). iOS exploit chain deploys LightSpy feature-rich malware. Retrieved January 13, 2025.
Open source URL - [41]MelikovBlackBerry LightSpy 2024
Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.
Open source URL - [42]Threatfabric LightSpy 2023
ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.
Open source URL - [43]Threatfabric LightSpy 2024
ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.
Open source URL - [44]LinkedIn Dmitry LightSpy 2025
Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.
Open source URL - [45]Lookout-Dendroid
Marc Rogers. (2014, March 6). Dendroid malware can take over your camera, record audio, and sneak into Google Play. Retrieved December 22, 2016.
Open source URL - [46]Lookout Dark Caracal Jan 2018
Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
Open source URL - [47]Zscaler TikTok Spyware
S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021.
Open source URL - [48]PaloAlto-SpyDealer
Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.
Open source URL - [49]NIST Mobile Threat CatalogueAPP-19Open source URL
- [50]NIST Mobile Threat CatalogueAPP-19Open source URL
- [51]mitre-attackT1512Open source URL
- [52]mitre-attackT1512Open source URL
- [53]Lookout Uyghur Campaign
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.
Open source URL - [54]TrendMicro Coronavirus Updates
T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.
Open source URL - [55]lookout_hornbill_sunbird_0221
Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
