LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1582: SMS Control

Adversaries may delete, alter, or send SMS messages without user authorization. This could be used to hide C2 SMS messages, spread malware, or various external effects.

This can be accomplished by requesting the `RECEIVE_SMS` or `SEND_SMS` permissions depending on what the malware is attempting to do. If the app is set as the default SMS handler on the device, the `SMS_DELIVER` broadcast intent can be registered, which allows the app to write to the SMS content provider. The content provider directly modifies the messaging database on the device, which could allow malicious applications with this ability to insert, modify, or delete arbitrary messages on the device.[1][2]

MobileT1582TechniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

SMS Control matters because a malicious Android app can send, alter, or delete text messages without the user’s authorization. That can undermine trust in SMS-based communications, hide SMS-based command messages, spread malware, or affect workflows that depend on SMS, including some banking and one-time-code scenarios reflected in related malware descriptions.

Executive priority

Treat this as a mobile risk and identity-readiness question: where does the organization still depend on SMS for authentication, approvals, customer contact, or operational coordination, and are Android devices in those workflows monitored well enough to identify risky SMS permissions or default SMS-handler changes? The ATT&CK relationships show this behavior across Android RATs, spyware, and banking malware, so it is useful for prioritizing mobile security controls, user guidance, and incident response playbooks involving compromised phones.

Technical view

For SOC, mobile security, and IR teams, validate Android coverage around apps requesting RECEIVE_SMS or SEND_SMS permissions, apps becoming the default SMS handler, registration for SMS_DELIVER, and access to the SMS content provider or messaging database. ATT&CK does not provide official detection text for T1582, but it does reference a related detection strategy, DET0599, and multiple Android software families that use the behavior. Detection logic should therefore be environment-specific and should combine app permission state, app reputation/inventory, SMS-handler role changes, and observed SMS activity rather than relying on a single permission as malicious.

Likely telemetry

  • Android app permission inventory, especially RECEIVE_SMS and SEND_SMS
  • Default SMS handler configuration and changes
  • Installed application inventory from MDM/EMM or mobile security tooling
  • Broadcast receiver or app manifest indicators related to SMS_DELIVER where available
  • SMS send/delete/modify events or messaging database/content provider activity where visibility exists

Detection direction

  • Confirm whether mobile telemetry can show which apps have SMS permissions and which app is the default SMS handler.
  • Tune for suspicious combinations: non-messaging apps requesting SMS permissions, newly installed apps gaining SMS access, or unexpected default SMS-handler changes.
  • Account for false positives from legitimate messaging, carrier, enterprise communication, or MFA-related apps that require SMS functionality.
  • Use relationship context to enrich triage: Android RATs, spyware, and banking trojans are listed as using this behavior, so SMS control should raise priority when paired with other remote-access, surveillance, or banking-malware indicators.
  • Document blind spots: ATT&CK provides no official detection procedure here, and many organizations have limited visibility into personal or unmanaged Android devices.

Mitigation priorities

  • Start with M1011 User Guidance: educate users to avoid granting SMS permissions to apps that do not clearly need them and to be cautious when an app asks to become the default SMS handler.
  • For managed Android fleets, review whether policy can restrict or alert on high-risk SMS permissions and default SMS-handler changes.
  • Reduce business dependence on SMS where feasible for sensitive authentication or approval workflows, especially where compromised Android devices could affect identity assurance.
  • Ensure mobile incident response playbooks include SMS abuse indicators, permission review, app removal, and assessment of any SMS-based business or authentication activity that may have been affected.
Additional notes and limits

This take is based on ATT&CK T1582 SMS Control for Android, its official description, external references to Android SMS handling and SmsProvider behavior, the related DET0599 detection strategy, M1011 User Guidance mitigation, and listed software relationships including Android RATs, spyware, and banking malware. The strongest defensive value is validating whether the organization can observe and govern SMS-related app permissions and default handler status.

ATT&CK does not specify tactics for this object and provides no official detection text in the supplied fields. DET0599 is referenced only by name, without its detection details. Local mobile management, privacy constraints, device ownership model, and Android version behavior will determine what telemetry and controls are actually available.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

SMS Control

Adversaries may delete, alter, or send SMS messages without user authorization. This could be used to hide C2 SMS messages, spread malware, or various external effects.

This can be accomplished by requesting the `RECEIVE_SMS` or `SEND_SMS` permissions depending on what the malware is attempting to do. If the app is set as the default SMS handler on the device, the `SMS_DELIVER` broadcast intent can be registered, which allows the app to write to the SMS content provider. The content provider directly modifies the messaging database on the device, which could allow malicious applications with this ability to insert, modify, or delete arbitrary messages on the device.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

MalwareMobile

S1054: Drinik

Drinik is an evolving Android banking trojan that was observed targeting customers of around 27 banks in India in August 2021. Initially seen as an SMS stealer in 2016, Drinik resurfaced as a banking trojan with more advanced capabilities included in subsequent versions between September 2021 and August 2022.[1]

Android
MalwareMobile

S0425: Corona Updates

Corona Updates is Android spyware that took advantage of the Coronavirus pandemic. The campaign distributing this spyware is tracked as Project Spy. Multiple variants of this spyware have been discovered to have been hosted on the Google Play Store.[1]

Android
MalwareMobile

S1067: FluBot

FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020. It primarily spread through European countries using a variety of SMS phishing messages in multiple languages.[1][2] An international law enforcement operation of 11 countries eventually disrupted the spread of FluBot.[3]

Android
MalwareMobile

S9004: Crocodilus

Crocodilus is an Android banking Trojan that was discovered in March 2025. Crocodilus targeted users worldwide, including Turkey, Poland, Argentina, Brazil, Spain, the United States, Indonesia and India. Crocodilus has been customized based on the target location. For example, Crocodilus mimicked major Turkish and Spanish banks for users in Turkey and Spain, while users in Poland saw Facebook advertisements that promoted Crocodilus to claim bonus points.[1][2]

Android
MalwareMobile

S0292: AndroRAT

AndroRAT is an open-source remote access tool for Android devices. AndroRAT is capable of collecting data, such as device location, call logs, etc., and is capable of executing actions, such as sending SMS messages and taking pictures.[1][2][3] It is originally available through the `The404Hacking` Github repository.[2]

Android
MalwareMobile

S0549: SilkBean

SilkBean is a piece of Android surveillanceware containing comprehensive remote access tool (RAT) functionality that has been used in targeting of the Uyghur ethnic group.[1]

Android
MalwareMobile

S0522: Exobot

Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.[1]

Android
MalwareMobile

S0328: Stealth Mango

Stealth Mango is Android malware that has reportedly been used to successfully compromise the mobile devices of government officials, members of the military, medical professionals, and civilians. The iOS malware known as Tangelo is believed to be from the same developer. [1]

Android
MalwareMobile

S0422: Anubis

Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.[1]

Android
MalwareMobile

S1195: SpyC23

SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017. SpyC23 has been observed primarily targeting Android devices in the Middle East.[1]

There are multiple close variants of SpyC23, such as VAMP[2], GnatSpy[3], Desert Scorpion and FrozenCell, which add some additional functionality but are not significantly different from the original malware.

Android
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
52dba4cc70722ef7...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle52dba4cc7072…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SMS KitKat

    S.Main, D. Braun. (2013, October 14). Getting Your SMS Apps Ready for KitKat. Retrieved September 11, 2020.

    Open source URL
  2. [2]
    Android SmsProvider

    Google. (n.d.). SmsProvider.java. Retrieved September 11, 2020.

    Open source URL
  3. [3]
    cyble_drinik_1022

    Cyble. (2022, October 27). Drinik Malware Returns With Advanced Capabilities Targeting Indian Taxpayers. Retrieved November 17, 2024.

    Open source URL
  4. [4]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  5. [5]
    proofpoint_flubot_0421

    Crista Giering, F. Naves, Andrew Conway, Adam McNeil . (2021, April 27). FluBot Android Malware Spreading Rapidly Through Europe, May Hit U.S. Soon. Retrieved February 28, 2023.

    Open source URL
  6. [6]
    bitdefender_flubot_0524

    Filip TRUȚĂ, Răzvan GOSA, Adrian Mihai GOZOB. (2022, May 24). New FluBot Campaign Sweeps through Europe Targeting Android and iOS Users Alike. Retrieved February 28, 2023.

    Open source URL
  7. [7]
    ThreatFabric_Crocodilus_March2025

    ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025.

    Open source URL
  8. [8]
    forcepoint_bitter

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved March 1, 2024.

    Open source URL
  9. [9]
    Talos GPlayed

    V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020.

    Open source URL
  10. [10]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  11. [11]
    Sophos Red Alert 2.0

    J. Chandraiah. (2018, July 23). Red Alert 2.0: Android Trojan targets security-seekers. Retrieved December 14, 2020.

    Open source URL
  12. [12]
    Threat Fabric Exobot

    Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020.

    Open source URL
  13. [13]
    Lookout-StealthMango

    Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.

    Open source URL
  14. [14]
    Cofense Anubis

    M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024.

    Open source URL
  15. [15]
    welivesecurity_apt-c-23

    Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.

    Open source URL
  16. [16]
    Talos-WolfRAT

    W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back... . Retrieved July 20, 2020.

    Open source URL
  17. [17]
    Zscaler TikTok Spyware

    S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021.

    Open source URL
  18. [18]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  19. [19]
    Threat Fabric Cerberus

    Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020.

    Open source URL
  20. [20]
    Lookout-Dendroid

    Marc Rogers. (2014, March 6). Dendroid malware can take over your camera, record audio, and sneak into Google Play. Retrieved December 22, 2016.

    Open source URL
  21. [21]
    nccgroup_sharkbot_0322

    RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023.

    Open source URL
  22. [22]
    Securelist Asacub

    T. Shishkova. (2018, August 28). The rise of mobile banker Asacub. Retrieved December 14, 2020.

    Open source URL
  23. [23]
    cloudmark_tanglebot_0921

    Felipe Naves, Andrew Conway, W. Stuart Jones, Adam McNeil . (2021, September 23). TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures. Retrieved February 28, 2023.

    Open source URL
  24. [24]
    Cybereason FakeSpy

    O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020.

    Open source URL
  25. [25]
    SecurityIntelligence TrickMo

    P. Asinovsky. (2020, March 24). TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany. Retrieved April 24, 2020.

    Open source URL
  26. [26]
    Lookout Desert Scorpion

    A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.

    Open source URL
  27. [27]
    SecureList BusyGasper

    Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021.

    Open source URL
  28. [28]
    threatfabric_sova_0921

    ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023.

    Open source URL
  29. [29]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  30. [30]
    securelist rotexy 2018

    T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019.

    Open source URL
  31. [31]
    MerkleScience_Godfather_April2023

    Merkle Science. (2023, April 25). The Godfather Android Malware: Threat under the lens. Retrieved July 16, 2025.

    Open source URL
  32. [32]
    welivesecurity_ahrat_0523

    Lukas Stefanko. (2023, May 23). Android app breaking bad: From legitimate screen recording to file exfiltration within a year. Retrieved December 18, 2023.

    Open source URL
  33. [33]
    Threatfabric LightSpy 2023

    ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.

    Open source URL
  34. [34]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  35. [35]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  36. [36]
    ThreatFabric Ginp

    ThreatFabric. (2019, November). Ginp - A malware patchwork borrowing from Anubis. Retrieved April 8, 2020.

    Open source URL
  37. [37]
    WhiteOps TERRACOTTA

    Satori Threat Intelligence and Research Team. (2020, August). TERRACOTTA Android Malware: A Technical Study. Retrieved December 18, 2020.

    Open source URL
  38. [38]
    Android SmsProvider

    Google. (n.d.). SmsProvider.java. Retrieved September 11, 2020.

    Open source URL
  39. [39]
    NIST Mobile Threat CatalogueAPP-16
    Open source URL
  40. [40]
    NIST Mobile Threat CatalogueAPP-16
    Open source URL
  41. [41]
    NIST Mobile Threat CatalogueCEL-41
    Open source URL
  42. [42]
    NIST Mobile Threat CatalogueCEL-41
    Open source URL
  43. [43]
    SMS KitKat

    S.Main, D. Braun. (2013, October 14). Getting Your SMS Apps Ready for KitKat. Retrieved September 11, 2020.

    Open source URL
  44. [44]
    mitre-attackT1582
    Open source URL
  45. [45]
    mitre-attackT1582
    Open source URL
  46. [46]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  47. [47]
    SMS KitKat

    S.Main, D. Braun. (2013, October 14). Getting Your SMS Apps Ready for KitKat. Retrieved September 11, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.