LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1544: Ingress Tool Transfer

Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions. Files may be copied from an external adversary-controlled system through the command and control channel or through alternate protocols with another tool such as FTP.

MobileT1544TechniqueObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Ingress Tool Transfer matters because a compromised mobile device may not be the end state; adversaries can bring in additional files, modules, validators, or implants to continue the operation. For leaders, this is a mobile resilience issue: Android and iOS devices used by executives, administrators, or regulated business functions may become staging points for follow-on activity if file transfer and mobile network visibility are weak.

Executive priority

Prioritize this technique where mobile devices have access to sensitive communications, identity workflows, financial apps, or executive data. ATT&CK links this behavior to multiple Android malware families and iOS-focused activity, including Operation Triangulation and TriangleDB, so risk owners should ask whether mobile monitoring, incident response collection, and egress visibility can show when a compromised device receives new tooling from C2 or alternate protocols such as FTP.

Technical view

For SOC, detection engineering, and IR teams, validate coverage around unexpected file delivery to Android and iOS devices after suspected compromise. ATT&CK does not provide native detection text for T1544, but relationship context includes DET0718, Detection of Ingress Tool Transfer. Practical validation should focus on whether mobile telemetry can correlate network sessions to external systems with file creation, package/module changes, or execution of newly delivered content. Android coverage is especially relevant given the number of related Android software entries; iOS coverage should be assessed separately because device-level telemetry is often more constrained.

Likely telemetry

  • Mobile device network metadata, including connections to external systems, C2-like infrastructure, and protocols such as FTP where visible
  • DNS, proxy, VPN, firewall, or secure web gateway logs for managed mobile traffic
  • Mobile threat defense, EDR, or MDM events showing downloaded files, new packages, changed app components, or suspicious modules
  • Android application/package inventory, install/update events, and file-system indicators where collection is available
  • iOS MDM, network, and forensic artifacts that can support investigation of externally delivered files or implants

Detection direction

  • Confirm whether DET0718 or equivalent analytics are implemented and mapped to Android and iOS mobile telemetry, rather than assuming desktop ingress-transfer logic applies to mobile.
  • Tune for sequences: suspected compromise or C2 communication followed by new file creation, module download, package change, or execution from unusual locations.
  • Account for false positives from legitimate app updates, enterprise content delivery, MDM actions, and user-initiated downloads; context from device ownership, app reputation, and destination reputation is important.
  • Review blind spots where mobile traffic bypasses corporate inspection, where BYOD devices lack MDM/MTD coverage, or where iOS telemetry cannot expose file-level activity without forensic collection.
  • Use relationship context for threat-informed testing: Android examples include RedDrop, Monokle, ViceLeaker, Mandrake, SharkBot, AbstractEmu, Sunbird, Chameleon, SpyC23, CherryBlos, GodFather, and DocSwap; iOS examples include Phenakite, TriangleDB, LightSpy, and Operation Triangulation.

Mitigation priorities

  • Start with mobile asset and enrollment coverage: identify which Android and iOS devices are managed, monitored, and eligible for incident response collection.
  • Reduce uncontrolled file delivery paths by enforcing approved app sources, mobile configuration baselines, and network controls appropriate to managed devices.
  • Improve egress visibility for mobile devices through managed VPN, DNS, proxy, or gateway logging where privacy and policy allow.
  • Harden response playbooks so suspected mobile compromise triggers containment, preservation, and review for additional tools or files delivered after initial access.
  • For high-risk users, validate mobile security posture alongside identity controls, since follow-on tooling on a device may affect communications, credentials, or sensitive application access.
Additional notes and limits

ATT&CK defines T1544 as transfer of tools or other files from an external system onto a compromised Android or iOS device, either through the command-and-control channel or alternate protocols such as FTP. The relationship set shows this behavior across numerous mobile malware and campaign objects, which supports prioritizing it as a cross-platform mobile defense concern rather than a niche artifact.

The official ATT&CK object provides no tactic assignment and no detection text. This take therefore avoids claiming specific detection efficacy or active customer exposure. Local device management model, telemetry depth, mobile OS restrictions, and legal/privacy constraints will determine what can actually be detected or investigated.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Ingress Tool Transfer

Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions. Files may be copied from an external adversary-controlled system through the command and control channel or through alternate protocols with another tool such as FTP.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

MalwareMobile

S1185: LightSpy

First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to Android and macOS platforms. It consists of a downloader, a main executable that manages network communications, and functionality-specific modules, typically implemented as `.dylib` files (iOS, macOS) or `.apk` files (Android). LightSpy can collect VoIP call recordings, SMS messages, and credential stores, which are then exfiltrated to a command and control (C2) server.[1]

AndroidWindowsiOS
MalwareMobile

S1083: Chameleon

Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities. Believed to have been first active in January 2023, Chameleon has been observed targeting users in Australia and Poland by masquerading as official applications. A new variant of Chameleon has expanded its targets to include Android users in the United Kingdom and Italy.[1][2]

Android
MalwareMobile

S1195: SpyC23

SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017. SpyC23 has been observed primarily targeting Android devices in the Middle East.[1]

There are multiple close variants of SpyC23, such as VAMP[2], GnatSpy[3], Desert Scorpion and FrozenCell, which add some additional functionality but are not significantly different from the original malware.

Android
MalwareMobile

S0418: ViceLeaker

ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices belonging to Israeli citizens.[1][2]

Android
MalwareMobile

S1126: Phenakite

Phenakite is a mobile malware that is used by APT-C-23 to target iOS devices. According to several reports, Phenakite was developed to fill a tooling gap and to target those who owned iPhones instead of Windows desktops or Android phones.[1][2]

iOS
MalwareMobile

S1055: SharkBot

SharkBot is a banking malware, first discovered in October 2021, that tries to initiate money transfers directly from compromised devices by abusing Accessibility Services.[1]

Android
MalwareMobile

S9005: DocSwap

DocSwap is an Android malware first identified in 2025, and attributed to Kimsuky. DocSwap’s name is a combination of its Korean name “문서열람 인증 앱” (Document Viewing Authentication App) and a phishing page masquerading as CoinSwap at the C2 address. Based on DocSwap’s name and Korean-language strings, DocSwap potentially targets mobile device users in South Korea. Several variants of DocSwap exist; one of the latest samples indicates that the adversary added a native decryption function that decrypts an internal APK.[1][2]

Android
MalwareMobile

S1231: GodFather

GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and other permissions to evade detection and exfiltrate sensitive data. First identified in 2020, GodFather targets nearly 500 banking applications, cryptocurrency wallets, and exchanges worldwide; however, its virtualization-based attacks have primarily focused on several Turkish financial institutions. This capability enables threat actors to steal banking credentials and other sensitive account information. [1][2]

Android
MalwareMobile

S0407: Monokle

Monokle is targeted, sophisticated mobile surveillanceware. It is developed for Android, but there are some code artifacts that suggests an iOS version may be in development.[1]

Android
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.2
Created
Modified
Raw hash
b0887e0db9feeafa...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.2Current bundleb0887e0db9fe…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SecureList OpTriangulation 21Jun2023

    Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.

    Open source URL
  2. [2]
    MelikovBlackBerry LightSpy 2024

    Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.

    Open source URL
  3. [3]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  4. [4]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  5. [5]
    SecureList OpTriangulation 01Jun2023

    Kuznetsov, I., et al. (2023, June 1). Operation Triangulation: iOS devices targeted with previously unknown malware. Retrieved April 18, 2024.

    Open source URL
  6. [6]
    cyble_chameleon_0423

    Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023.

    Open source URL
  7. [7]
    welivesec_strongpity

    Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.

    Open source URL
  8. [8]
    welivesecurity_apt-c-23

    Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.

    Open source URL
  9. [9]
    checkpoint_hamas_android_malware

    CheckPoint Research. (2020, February 16). Hamas Android Malware On IDF Soldiers-This is How it Happened. Retrieved November 17, 2024.

    Open source URL
  10. [10]
    SentinelLabs AridViper 2023

    Delamotte, A. (2023, November 6). Arid Viper | APT’s Nest of SpyC23 Malware Continues to Target Android Devices. Retrieved December 2, 2024.

    Open source URL
  11. [11]
    SecureList - ViceLeaker 2019

    GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.

    Open source URL
  12. [12]
    fb_arid_viper

    Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.

    Open source URL
  13. [13]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  14. [14]
    nccgroup_sharkbot_0322

    RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023.

    Open source URL
  15. [15]
    Wandera-RedDrop

    Nell Campbell. (2018, February 27). RedDrop: the blackmailing mobile malware family lurking in app stores. Retrieved November 17, 2024.

    Open source URL
  16. [16]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  17. [17]
    S2W_DocSwap_Mar2025

    Kim, H., S2W TALON. (2025, March 13). Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer. Retrieved January 12, 2026.

    Open source URL
  18. [18]
    ZimperiumOrtegaPratapagiri_GodFather_Jun2025

    Ortega, F. Pratapagiri, V. (2025, June 18). Your Mobile App, Their Playground: The Dark Side of Virtualization. Retrieved July 16, 2025.

    Open source URL
  19. [19]
    Lookout-Monokle

    Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019.

    Open source URL
  20. [20]
    lookout_abstractemu_1021

    P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.

    Open source URL
  21. [21]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  22. [22]
    TrendMicro_CherryBlos_July2023

    Trend Micro Research. (2023, July 28). Related CherryBlos and FakeTrade Android Malware Involved in Scam Campaigns. Retrieved March 28, 2025.

    Open source URL
  23. [23]
    mitre-attackT1544
    Open source URL
  24. [24]
    mitre-attackT1544
    Open source URL
  25. [25]
    SecureList OpTriangulation 21Jun2023

    Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.