LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1532: Archive Collected Data

Adversaries may compress and/or encrypt data that is collected prior to exfiltration. Compressing data can help to obfuscate its contents and minimize use of network resources. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.

Both compression and encryption are done prior to exfiltration, and can be performed using a utility, programming library, or custom algorithm.

MobileT1532TechniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Archive Collected Data is a mobile ATT&CK technique where an adversary compresses and/or encrypts information already gathered from a device before trying to exfiltrate it. For leaders, the practical issue is not the archive itself; it is that stolen mobile data may be made smaller, harder to inspect, and less obvious in network traffic. This matters for organizations that rely on Android or iOS devices for executive communications, banking, field operations, regulated data access, or incident communications.

Executive priority

Treat this as a mobile data-loss and incident-response readiness concern. ATT&CK maps the behavior to Android and iOS, and relationship context links it to multiple Android malware and spyware families, plus a documented mobile campaign. Security leaders should ask whether mobile telemetry, MDM/MAM controls, app vetting, and network monitoring can show when sensitive device data is being staged and prepared for exfiltration. The priority is strongest where mobile devices access regulated data, financial workflows, executive communications, or operational systems.

Technical view

SOC and IR teams should validate visibility for suspicious compression, encryption, or archive creation by mobile apps before outbound transfer. ATT&CK does not provide official detection text for T1532, but a related detection strategy, DET0670, is listed. Since tactics are not specified in the supplied object, detection should be anchored to the observable behavior: collected files or records being bundled, encrypted, and then followed by network activity. Relationship context is heavily Android-focused, with one related software entry also covering iOS, so Android telemetry may be richer while iOS validation should account for platform visibility limits.

Likely telemetry

  • Mobile device management or mobile application management inventory, compliance, and app installation events
  • Mobile threat defense or mobile EDR alerts for suspicious app behavior
  • Android application, file-system, sandbox, or storage-access events where available
  • iOS device, app, and network telemetry where enterprise controls permit collection
  • Evidence of archive, compressed, or encrypted file creation in app-accessible storage

Detection direction

  • Validate whether DET0670 or local analytics look for compression/encryption staging followed by outbound transfer, rather than only known malware names.
  • Correlate archive-like file creation or encryption behavior with apps that have sensitive permissions or unusual access to collected data.
  • Tune for false positives from legitimate backup, messaging, productivity, VPN, and enterprise sync applications that compress or encrypt data normally.
  • Use relationship context to prioritize testing against Android scenarios, while separately confirming what is realistically observable on iOS.
  • Look for behavioral chains: data collection, local bundling or encryption, then network communication to uncommon or newly observed destinations.

Mitigation priorities

  • Prioritize mobile app governance: approved app stores, app vetting, removal of unauthorized apps, and controls for sideloading where applicable.
  • Use MDM/MAM policy to limit risky permissions, separate work data from personal apps, and enforce compliance for devices accessing enterprise resources.
  • Reduce mobile data exposure by limiting what sensitive data is stored locally or made available to unmanaged apps.
  • Apply mobile threat defense or equivalent monitoring where business risk justifies it, especially for high-risk users and regulated workflows.
  • Control and monitor mobile egress through managed VPN, DNS, proxy, or secure web gateway paths where feasible.
Additional notes and limits

The supplied ATT&CK object is a mobile technique for Android and iOS. Official detection guidance is not provided, and tactics are not specified. Relationships show use by campaign C0033 and multiple software entries including Exodus, GolfSpy, Anubis, Triada, Desert Scorpion, Golden Cup, Asacub, FrozenCell, BOULDSPY, Sunbird, BRATA, LightSpy, and DCHSpy. Most related software entries are Android-focused; LightSpy includes Android and iOS among other platforms.

This take is limited to the supplied ATT&CK fields, external reference, and relationship context. It does not establish active exploitation, attribution against any organization, or guaranteed detection coverage. Local device management, mobile OS restrictions, privacy rules, network architecture, and logging configuration determine what can actually be observed.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Archive Collected Data

Adversaries may compress and/or encrypt data that is collected prior to exfiltration. Compressing data can help to obfuscate its contents and minimize use of network resources. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.

Both compression and encryption are done prior to exfiltration, and can be performed using a utility, programming library, or custom algorithm.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

MalwareMobile

S0405: Exodus

Exodus is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).[1]

Android
MalwareMobile

S1079: BOULDSPY

BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities. Analysis of exfiltrated C2 data suggests that BOULDSPY primarily targeted minority groups in Iran.[1]

Android
MalwareMobile

S0422: Anubis

Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.[1]

Android
MalwareMobile

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
MalwareMobile

S1094: BRATA

BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021. Originating in Brazil, BRATA was later also found in the UK, Poland, Italy, Spain, and USA, where it is believed to have targeted financial institutions such as banks. There are currently three known variants of BRATA.[1][2][3]

Android
MalwareMobile

S0424: Triada

Triada was first reported in 2016 as a second stage malware. Later versions in 2019 appeared with new techniques and as an initial downloader of other Trojan apps.[1]

Android
MalwareMobile

S1243: DCHSpy

DCHSpy is an Android spyware likely used by MuddyWater. DCHSpy uses political decoys and masquerades as legitimate applications, such as VPNs and banking applications, to trick victims into downloading the malware. Once downloaded, DCHSpy collects information from the device and exfiltrates the data to the command and control (C2) server.[1]

Android
MalwareMobile

S0540: Asacub

Asacub is a banking trojan that attempts to steal money from victims’ bank accounts. It attempts to do this by initiating a wire transfer via SMS message from compromised devices.[1]

Android
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
fb77a4bcebed283c...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundlefb77a4bcebed…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Lookout Desert Scorpion

    A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.

    Open source URL
  2. [2]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    lookout_bouldspy_0423

    Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.

    Open source URL
  4. [4]
    Cofense Anubis

    M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024.

    Open source URL
  5. [5]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  6. [6]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  7. [7]
    cleafy_brata_0122

    Federico Valentini, Francesco Lubatti. (2022, January 24). How BRATA is monitoring your bank account. Retrieved December 18, 2023.

    Open source URL
  8. [8]
    Google Triada June 2019

    Lukasz Siewierski. (2019, June 6). PHA Family Highlights: Triada. Retrieved July 16, 2019.

    Open source URL
  9. [9]
    welivesec_strongpity

    Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.

    Open source URL
  10. [10]
    Symantec GoldenCup

    R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020.

    Open source URL
  11. [11]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  12. [12]
    Lookout_DCHSpy_July2025

    Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025.

    Open source URL
  13. [13]
    Lookout FrozenCell

    Michael Flossman. (2017, October 5). FrozenCell: Multi-platform surveillance campaign against Palestinians. Retrieved November 11, 2020.

    Open source URL
  14. [14]
    Securelist Asacub

    T. Shishkova. (2018, August 28). The rise of mobile banker Asacub. Retrieved December 14, 2020.

    Open source URL
  15. [15]
    Trend Micro Bouncing Golf 2019

    E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020.

    Open source URL
  16. [16]
    mitre-attackT1532
    Open source URL
  17. [17]
    mitre-attackT1532
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.