LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1630.002: File Deletion

Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity. An application must have administrator access to fully wipe the device, while individual files may not require special permissions to delete depending on their storage location.[1]

Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The impact file deletion will have depends on the type of data as well as the goals and objectives of the adversary, but can include deleting update files to evade detection or deleting attacker-specified files for impact.

MobileT1630.002Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

File Deletion (T1630.002) matters because a mobile app can remove evidence or business data from an Android device, and full device wipe requires administrator access. For leaders, the key issue is not just malware cleanup; it is whether mobile security, MDM, and incident response processes can preserve evidence and recover from targeted deletion of documents, databases, stored emails, update files, or other local data.

Executive priority

Prioritize this where Android devices hold regulated data, operational records, executive communications, or field-worker information. Ask whether users can grant administrator access to untrusted apps, whether mobile incidents preserve evidence before remote cleanup, and whether audit/compliance evidence depends on data that may exist only on the device. The supplied ATT&CK relationships show this behavior is used by multiple mobile malware and surveillanceware entries, making it a practical coverage question for mobile security programs rather than a theoretical edge case.

Technical view

ATT&CK lists this as an Android mobile sub-technique of Indicator Removal on Host (T1630). The official detection field is not provided, but a related detection strategy, DET0638 Detection of File Deletion, exists. SOC and IR teams should validate visibility into device administrator status, wipe-related actions through Android DevicePolicyManager-relevant controls, and file deletion activity in app-accessible storage locations where collection is feasible. Because individual file deletion may not require special permissions depending on storage location, detection should not rely only on administrator-access events. Relationship context includes many Android software entries using this behavior; it also includes some iOS-related mobile objects, so defenders should treat the platform scope carefully and validate against their own mobile fleet rather than assuming identical telemetry across platforms.

Likely telemetry

  • Android device administrator enablement or policy-change events
  • MDM or mobile security alerts for device wipe or destructive device-management actions
  • Mobile EDR or on-device security events indicating unusual file deletion
  • Application permission, installation, and behavior records for apps with access to sensitive storage locations
  • Filesystem or app-storage change evidence where the mobile security stack can collect it

Detection direction

  • Confirm what DET0638-style file deletion coverage means in the environment, since no official detection logic is supplied in the ATT&CK object.
  • Tune for destructive activity by apps with administrator access, but also look for deletion in storage locations where special permissions may not be required.
  • Correlate deletion events with suspicious app installation, permission changes, device administrator grants, and mobile security alerts.
  • Account for false positives from legitimate user cleanup, app updates, storage management, and approved remote wipe workflows.
  • Validate whether evidence is retained off-device; this technique may interfere with event collection and reporting as part of Indicator Removal on Host.

Mitigation priorities

  • Use the supplied M1011 User Guidance mitigation: train users to avoid granting risky permissions or administrator access to untrusted applications.
  • Review mobile configuration standards so administrator-capable apps and wipe-capable management functions are limited to approved use cases.
  • Ensure incident response playbooks prioritize evidence preservation before routine device reset or cleanup when suspicious deletion is suspected.
  • For higher-risk Android populations, validate mobile security and management controls against file deletion and wipe scenarios in testing rather than assuming coverage.
Additional notes and limits

This object replaces/revokes older T1447 Delete Device Data and is a sub-technique of T1630 Indicator Removal on Host. The behavior is associated through ATT&CK relationships with multiple mobile software entries including Pallas, Monokle, FlexiSpy, ViceLeaker, GolfSpy, Agent Smith, Mandrake, WolfRAT, Desert Scorpion, CarbonSteal, GPlayed, SilkBean, DoubleAgent, Tiktok Pro, Hornbill, Fakecalls, DocSwap, and others, plus Operation Triangulation-related mobile objects. These relationships support prioritizing mobile visibility and IR readiness, but they do not by themselves prove exposure in any specific environment.

ATT&CK provides no official detection text for this object, and the tactic field is not specified. The main object platform is Android, while some relationship context references iOS mobile objects; local platform scoping and telemetry validation are required. This take does not assert active exploitation, customer exposure, attribution, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

File Deletion

Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity. An application must have administrator access to fully wipe the device, while individual files may not require special permissions to delete depending on their storage location.[1]

Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The impact file deletion will have depends on the type of data as well as the goals and objectives of the adversary, but can include deleting update files to evade detection or deleting attacker-specified files for impact.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
MobileT1447Delete Device DataDelete Device Data revoked by this object.
MobileT1630Indicator Removal on HostThis object subtechnique of Indicator Removal on Host.
Associated objects

Groups, software, and campaigns

MalwareMobile

S0407: Monokle

Monokle is targeted, sophisticated mobile surveillanceware. It is developed for Android, but there are some code artifacts that suggests an iOS version may be in development.[1]

Android
MalwareMobile

S0549: SilkBean

SilkBean is a piece of Android surveillanceware containing comprehensive remote access tool (RAT) functionality that has been used in targeting of the Uyghur ethnic group.[1]

Android
MalwareMobile

S0440: Agent Smith

Agent Smith is mobile malware that generates financial gain by replacing legitimate applications on devices with malicious versions that include fraudulent ads. As of July 2019 Agent Smith had infected around 25 million devices, primarily targeting India though effects had been observed in other Asian countries as well as Saudi Arabia, the United Kingdom, and the United States.[1]

Android
MalwareMobile

S1080: Fakecalls

Fakecalls is an Android trojan, first detected in January 2021, that masquerades as South Korean banking apps. It has capabilities to intercept calls to banking institutions and even maintain realistic dialogues with the victim using pre-recorded audio snippets.[1]

Android
MalwareMobile

S0418: ViceLeaker

ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices belonging to Israeli citizens.[1][2]

Android
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
c98316c3d87b7946...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundlec98316c3d87b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Android DevicePolicyManager 2019

    Android Developers. (n.d.). DevicePolicyManager. Retrieved September 22, 2019.

    Open source URL
  2. [2]
    SecureList OpTriangulation 21Jun2023

    Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.

    Open source URL
  3. [3]
    lookout_hornbill_sunbird_0221

    Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023.

    Open source URL
  4. [4]
    Talos-WolfRAT

    W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back... . Retrieved July 20, 2020.

    Open source URL
  5. [5]
    Lookout-Monokle

    Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019.

    Open source URL
  6. [6]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  7. [7]
    Lookout Dark Caracal Jan 2018

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

    Open source URL
  8. [8]
    CheckPoint Agent Smith

    A. Hazum, F. He, I. Marom, B. Melnykov, A. Polkovnichenko. (2019, July 10). Agent Smith: A New Species of Mobile Malware. Retrieved May 7, 2020.

    Open source URL
  9. [9]
    Lookout Desert Scorpion

    A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.

    Open source URL
  10. [10]
    Talos GPlayed

    V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020.

    Open source URL
  11. [11]
    kaspersky_fakecalls_0422

    Igor Golovin. (2022, April 11). Fakecalls: a talking Trojan. Retrieved July 21, 2023.

    Open source URL
  12. [12]
    SecureList - ViceLeaker 2019

    GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.

    Open source URL
  13. [13]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  14. [14]
    S2W_DocSwap_Mar2025

    Kim, H., S2W TALON. (2025, March 13). Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer. Retrieved January 12, 2026.

    Open source URL
  15. [15]
    CyberMerchants-FlexiSpy

    Actis B. (2017, April 22). FlexSpy Application Analysis. Retrieved September 4, 2019.

  16. [16]
    Zscaler TikTok Spyware

    S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021.

    Open source URL
  17. [17]
    SecureList OpTriangulation 23Oct2023

    Kucherin, G., et al. (2023, October 23). The outstanding stealth of Operation Triangulation. Retrieved April 18, 2024.

    Open source URL
  18. [18]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  19. [19]
    Trend Micro Bouncing Golf 2019

    E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020.

    Open source URL
  20. [20]
    Android DevicePolicyManager 2019

    Android Developers. (n.d.). DevicePolicyManager. Retrieved September 22, 2019.

    Open source URL
  21. [21]
    mitre-attackT1630.002
    Open source URL
  22. [22]
    mitre-attackT1630.002
    Open source URL
  23. [23]
    SecureList OpTriangulation 21Jun2023

    Kucherin, G., et al. (2023, June 21). Dissecting TriangleDB, a Triangulation spyware implant. Retrieved April 18, 2024.

    Open source URL
  24. [24]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  25. [25]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.