LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1633.001: System Checks

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behavior after checking for the presence of artifacts indicative of a virtual environment or sandbox. If the adversary detects a virtual environment, they may alter their malware’s behavior to disengage from the victim or conceal the core functions of the implant. They may also search for virtualization artifacts before dropping secondary or additional payloads.

Checks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size.

Hardware checks, such as the presence of motion sensors, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.

MobileT1633.001Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

System Checks is mobile malware behavior where an app looks for signs it is running in an emulator, sandbox, or analysis environment before revealing its real functionality. For leaders, the practical issue is assurance: automated mobile app vetting can miss malicious behavior if the test environment looks unrealistic.

Executive priority

Prioritize this where Android or iOS devices support sensitive workflows, identity access, banking/payment activity, executive communications, or field operations. The business question is whether mobile security controls can evaluate suspicious apps in realistic conditions and produce evidence for incident response, audit, and risk decisions—not just whether an app was scanned once.

Technical view

ATT&CK lists Android and iOS platforms and no specific tactic or official detection text. Validate coverage against the related detection strategy DET0625 and the parent technique Virtualization/Sandbox Evasion. SOC and IR teams should look for apps that query environment indicators such as host or domain properties, network traffic patterns, network adapter addresses, CPU core count, memory or storage size, and sensor readings such as motion data, especially when those checks appear to gate payload delivery or change app behavior. Relationship context shows this behavior is documented across multiple Android malware entries, including banking trojans, RATs, spyware, adware, and related mobile threats, so Android telemetry depth is especially important.

Likely telemetry

  • Mobile threat defense or mobile EDR alerts and behavioral traces
  • MDM/UEM app inventory, install source, device posture, and compliance state
  • Mobile sandbox or dynamic analysis logs showing system property, hardware, network, and sensor queries
  • Static analysis results for emulator, sandbox, hardware, sensor, and environment-checking code paths
  • Network telemetry from mobile devices or analysis environments

Detection direction

  • Confirm that mobile analysis environments expose realistic device properties, storage, memory, network, and sensor activity; weak sandboxes may cause malware to hide.
  • Tune detections for suspicious combinations of system, hardware, network, and sensor checks followed by behavioral changes, rather than treating every hardware query as malicious.
  • Account for false positives: legitimate apps may check CPU, memory, storage, network state, or sensors for performance and feature support.
  • Compare behavior between sandbox/emulator and real-device analysis where legally and operationally appropriate.
  • Use ATT&CK relationship context to test against known mobile malware patterns, while avoiding assumptions that any single check proves compromise.

Mitigation priorities

  • Strengthen mobile app vetting with dynamic analysis that simulates realistic devices, networks, and sensor activity.
  • Use MDM/UEM policy to limit untrusted app sources and maintain app inventory and device compliance evidence.
  • Prioritize mobile threat monitoring for devices handling sensitive identity, financial, executive, or operational workflows.
  • In incident response, preserve app samples, device context, install source, permissions, network activity, and analysis-environment results for repeatable evidence.
  • Review mobile security testing procedures so sandbox-evasion findings drive escalation rather than a simple pass/fail result.
Additional notes and limits

This object is a sub-technique of T1633 Virtualization/Sandbox Evasion and supersedes revoked technique T1523. The supplied relationships include one detection strategy, one group, and multiple software entries, mostly Android, that use this behavior. That supports treating it as a material mobile analysis and detection-resilience concern, not as proof of current activity in any environment.

MITRE provides no official detection text and no tactic value for this object. Local conclusions require organization-specific mobile telemetry, app inventory, sandbox design, and device-use context. The supplied fields support Android and iOS platform relevance, but most named software relationships provided are Android-focused.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

System Checks

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behavior after checking for the presence of artifacts indicative of a virtual environment or sandbox. If the adversary detects a virtual environment, they may alter their malware’s behavior to disengage from the victim or conceal the core functions of the implant. They may also search for virtualization artifacts before dropping secondary or additional payloads.

Checks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size.

Hardware checks, such as the presence of motion sensors, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
MobileT1633Virtualization/Sandbox EvasionThis object subtechnique of Virtualization/Sandbox Evasion.
MobileT1523Evade Analysis EnvironmentEvade Analysis Environment revoked by this object.
Associated objects

Groups, software, and campaigns

GroupMobile

G0112: Windshift

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.[1][2][3]

MalwareMobile

S1061: AbstractEmu

AbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021. It was discovered in 19 Android applications, of which at least 7 abused known Android exploits for obtaining root permissions. AbstractEmu was observed primarily impacting users in the United States, however victims are believed to be across a total of 17 countries.[1]

Android
MalwareMobile

S0301: Dendroid

Dendroid is an Android remote access tool (RAT) primarily targeting Western countries. The RAT was available for purchase for $300 and came bundled with a utility to inject the RAT into legitimate applications.[1]

Android
MalwareMobile

S0485: Mandrake

Mandrake is a sophisticated Android espionage platform that has been active in the wild since at least 2016. Mandrake is very actively maintained, with sophisticated features and attacks that are executed with surgical precision.

Mandrake has gone undetected for several years by providing legitimate, ad-free applications with social media and real reviews to back the apps. The malware is only activated when the operators issue a specific command.[1]

Android
MalwareMobile

S0423: Ginp

Ginp is an Android banking trojan that has been used to target Spanish banks. Some of the code was taken directly from Anubis.[1]

Android
MalwareMobile

S0544: HenBox

HenBox is Android malware that attempts to only execute on Xiaomi devices running the MIUI operating system. HenBox has primarily been used to target Uyghurs, a minority Turkic ethnic group.[1]

Android
MalwareMobile

S1083: Chameleon

Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities. Believed to have been first active in January 2023, Chameleon has been observed targeting users in Australia and Poland by masquerading as official applications. A new variant of Chameleon has expanded its targets to include Android users in the United Kingdom and Italy.[1][2]

Android
MalwareMobile

S0480: Cerberus

Cerberus is a banking trojan whose usage can be rented on underground forums and marketplaces. Prior to being available to rent, the authors of Cerberus claim was used in private operations for two years.[1]

Android
MalwareMobile

S0411: Rotexy

Rotexy is an Android banking malware that has evolved over several years. It was originally an SMS spyware Trojan first spotted in October 2014, and since then has evolved to contain more features, including ransomware functionality.[1]

Android
MalwareMobile

S0509: FakeSpy

FakeSpy is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.[1]

Android
MalwareMobile

S0422: Anubis

Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.[1]

Android
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
d1f41ac3c5ff3c81...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundled1f41ac3c5ff…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    lookout_abstractemu_1021

    P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.

    Open source URL
  2. [2]
    WeLiveSecurity AdDisplayAshas

    L. Stefanko. (2019, October 24). Tracking down the developer of Android adware affecting millions of users. Retrieved October 29, 2020.

    Open source URL
  3. [3]
    Lookout-Dendroid

    Marc Rogers. (2014, March 6). Dendroid malware can take over your camera, record audio, and sneak into Google Play. Retrieved December 22, 2016.

    Open source URL
  4. [4]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  5. [5]
    ThreatFabric Ginp

    ThreatFabric. (2019, November). Ginp - A malware patchwork borrowing from Anubis. Retrieved April 8, 2020.

    Open source URL
  6. [6]
    Palo Alto HenBox

    A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.

    Open source URL
  7. [7]
    cyble_chameleon_0423

    Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023.

    Open source URL
  8. [8]
    WhiteOps TERRACOTTA

    Satori Threat Intelligence and Research Team. (2020, August). TERRACOTTA Android Malware: A Technical Study. Retrieved December 18, 2020.

    Open source URL
  9. [9]
    BlackBerry Bahamut

    The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.

    Open source URL
  10. [10]
    Threat Fabric Cerberus

    Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020.

    Open source URL
  11. [11]
    securelist rotexy 2018

    T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019.

    Open source URL
  12. [12]
    Cybereason FakeSpy

    O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020.

    Open source URL
  13. [13]
    Trend Micro Anubis

    K. Sun. (2019, January 17). Google Play Apps Drop Anubis, Use Motion-based Evasion. Retrieved January 20, 2021.

    Open source URL
  14. [14]
    mcafee_brata_0421

    Fernando Ruiz. (2021, April 12). BRATA Keeps Sneaking into Google Play, Now Targeting USA and Spain. Retrieved December 18, 2023.

    Open source URL
  15. [15]
    Talos-WolfRAT

    W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back... . Retrieved July 20, 2020.

    Open source URL
  16. [16]
    SecurityIntelligence TrickMo

    P. Asinovsky. (2020, March 24). TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany. Retrieved April 24, 2020.

    Open source URL
  17. [17]
    mitre-attackT1633.001
    Open source URL
  18. [18]
    mitre-attackT1633.001
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.