LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1636.004: SMS Messages

Adversaries may utilize standard operating system APIs to gather SMS messages. On Android, this can be accomplished using the SMS Content Provider. iOS provides no standard API to access SMS messages.

If the device has been jailbroken or rooted, an adversary may be able to access SMS Messages without the user’s knowledge or approval.

MobileT1636.004Sub-techniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

SMS message access on mobile devices matters because SMS can contain sensitive personal, business, and authentication information. In ATT&CK, this sub-technique covers adversaries using mobile OS capabilities to gather SMS messages: Android can expose SMS through the SMS Content Provider, while iOS has no standard SMS access API unless the device is jailbroken or otherwise compromised.

Executive priority

Treat this as a mobile data-protection and identity-risk issue, especially where SMS is used for account recovery, notifications, or multi-factor authentication. Leaders should ask whether managed mobile devices are monitored for risky app permissions, rooting or jailbreaking, and unauthorized apps, and whether user guidance is documented as compliance evidence. The relationship history shows this behavior is mapped to multiple mobile malware families and campaigns in ATT&CK, so it should be considered in mobile threat modeling even though the supplied object does not provide active-exploitation claims.

Technical view

For SOC, detection engineering, and IR teams, validate coverage on Android and iOS separately. On Android, focus on apps requesting or using SMS-related permissions and access to SMS-backed data stores. On iOS, standard app telemetry is unlikely to show normal SMS API use because MITRE states no standard API exists; investigation should emphasize jailbreak/root indicators and suspicious mobile security alerts. Because ATT&CK provides no official detection text for this technique, teams should use the related DET0686 detection strategy as a mapping point but confirm what telemetry and logic are actually available in their environment.

Likely telemetry

  • Mobile device management or unified endpoint management inventory for Android and iOS devices
  • Installed mobile application inventory and application provenance
  • Android application manifest and permission grant data related to SMS access
  • Mobile threat defense or endpoint telemetry for suspicious app behavior
  • Rooting and jailbreaking status indicators

Detection direction

  • Baseline which approved Android applications legitimately require SMS permissions, then alert or review unusual, newly installed, or unapproved apps requesting those permissions.
  • Separate Android and iOS detection assumptions: Android may expose SMS through permission-backed mechanisms, while iOS SMS access should raise concern primarily in the context of jailbreak or deeper device compromise.
  • Tune for false positives from legitimate messaging, device-management, authentication, or carrier-related applications that may have valid SMS-related functions.
  • Correlate SMS access concern with parent Protected User Data behavior, risky permission requests, app sideloading or untrusted provenance, and root/jailbreak indicators.
  • Document detection gaps explicitly, since the ATT&CK object does not include official detection guidance.

Mitigation priorities

  • Prioritize user guidance, as mapped by MITRE mitigation M1011: train users to avoid granting unnecessary permissions and to report unexpected SMS permission prompts or suspicious apps.
  • Restrict mobile app installation sources and maintain an approved application baseline where device management supports it.
  • Review whether SMS is used for authentication or account recovery and account for the risk that mobile malware may capture SMS content on affected devices.
  • Enforce mobile device compliance checks for rooted or jailbroken devices before granting access to business resources.
  • Use mobile security controls and IR playbooks to support investigation and containment when SMS access by an untrusted app is suspected.
Additional notes and limits

This object is a mobile ATT&CK sub-technique under Protected User Data and supersedes the revoked Capture SMS Messages technique relationship. The supplied relationships map it to several campaigns, groups, and software entries, including Android and iOS examples, but those relationships should be used for context and prioritization rather than as evidence of current activity in any specific environment.

ATT&CK provides no official detection text and no tactics for this object in the supplied fields. Detection feasibility depends heavily on mobile management, mobile threat defense, OS version, device ownership model, and whether devices are rooted or jailbroken. Local telemetry is required to determine actual coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

SMS Messages

Adversaries may utilize standard operating system APIs to gather SMS messages. On Android, this can be accomplished using the SMS Content Provider. iOS provides no standard API to access SMS messages.

If the device has been jailbroken or rooted, an adversary may be able to access SMS Messages without the user’s knowledge or approval.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
MobileT1412Capture SMS MessagesCapture SMS Messages revoked by this object.
MobileT1636Protected User DataThis object subtechnique of Protected User Data.
Associated objects

Groups, software, and campaigns

GroupMobile

G0112: Windshift

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.[1][2][3]

MalwareMobile

S0418: ViceLeaker

ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices belonging to Israeli citizens.[1][2]

Android
MalwareMobile

S0329: Tangelo

Tangelo is iOS malware that is believed to be from the same developers as the Stealth Mango Android malware. It is not a mobile application, but rather a Debian package that can only run on jailbroken iOS devices. [1]

iOS
MalwareMobile

S1092: Escobar

Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.[1]

Android
MalwareMobile

S0544: HenBox

HenBox is Android malware that attempts to only execute on Xiaomi devices running the MIUI operating system. HenBox has primarily been used to target Uyghurs, a minority Turkic ethnic group.[1]

Android
MalwareMobile

S0309: Adups

Adups is software that was pre-installed onto Android devices, including those made by BLU Products. The software was reportedly designed to help a Chinese phone manufacturer monitor user behavior, transferring sensitive data to a Chinese server. [1] [2]

MalwareMobile

S0432: Bread

Bread was a large-scale billing fraud malware family known for employing many different cloaking and obfuscation techniques in an attempt to continuously evade Google Play Store’s malware detection. 1,700 unique Bread apps were detected and removed from the Google Play Store before being downloaded by users.[1]

Android
MalwareMobile

S0423: Ginp

Ginp is an Android banking trojan that has been used to target Spanish banks. Some of the code was taken directly from Anubis.[1]

Android
MalwareMobile

S0301: Dendroid

Dendroid is an Android remote access tool (RAT) primarily targeting Western countries. The RAT was available for purchase for $300 and came bundled with a utility to inject the RAT into legitimate applications.[1]

Android
MalwareMobile

S1062: S.O.V.A.

S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of applications, including banking, cryptocurrency wallet/exchange, and shopping apps. S.O.V.A., which is Russian for "owl", contains features not commonly found in Android malware, such as session cookie theft.[1][2]

Android
CampaignMobile

C0016: Operation Dust Storm

Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast Asian countries. By 2015, the Operation Dust Storm threat actors shifted from government and defense-related intelligence targets to Japanese companies or Japanese subdivisions of larger foreign organizations supporting Japan's critical infrastructure, including electricity generation, oil and natural gas, finance, transportation, and construction.[1]

Operation Dust Storm threat actors also began to use Android backdoors in their operations by 2015, with all identified victims at the time residing in Japan or South Korea.[1]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
d3e8ef12bb4b3f46...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundled3e8ef12bb4b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    SecureList - ViceLeaker 2019

    GReAT. (2019, June 26). ViceLeaker Operation: mobile espionage targeting Middle East. Retrieved November 21, 2019.

    Open source URL
  2. [2]
    Lookout-StealthMango

    Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.

    Open source URL
  3. [3]
    Bleeipng Computer Escobar

    B. Toulas. (2022, March 12). Android malware Escobar steals your Google Authenticator MFA codes. Retrieved September 28, 2023.

    Open source URL
  4. [4]
    welivesec_strongpity

    Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023.

    Open source URL
  5. [5]
    Palo Alto HenBox

    A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019.

    Open source URL
  6. [6]
    NYTimes-BackDoor

    Matt Apuzzo and Michael S. Schmidt. (2016, November 15). Secret Back Door in Some U.S. Phones Sent Data to China, Analysts Say. Retrieved February 6, 2017.

    Open source URL
  7. [7]
    Google Bread

    A. Guertin, V. Kotov, Android Security & Privacy Team. (2020, January 9). PHA Family Highlights: Bread (and Friends) . Retrieved April 27, 2020.

    Open source URL
  8. [8]
    ThreatFabric Ginp

    ThreatFabric. (2019, November). Ginp - A malware patchwork borrowing from Anubis. Retrieved April 8, 2020.

    Open source URL
  9. [9]
    TrendMicro-RCSAndroid

    Veo Zhang. (2015, July 21). Hacking Team RCSAndroid Spying Tool Listens to Calls; Roots Devices to Get In. Retrieved December 22, 2016.

  10. [10]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  11. [11]
    Lookout-Dendroid

    Marc Rogers. (2014, March 6). Dendroid malware can take over your camera, record audio, and sneak into Google Play. Retrieved December 22, 2016.

    Open source URL
  12. [12]
    threatfabric_sova_0921

    ThreatFabric. (2021, September 9). S.O.V.A. - A new Android Banking trojan with fowl intentions. Retrieved February 6, 2023.

    Open source URL
  13. [13]
    FireEye-RuMMS

    Wu Zhou, Deyu Hu, Jimmy Su, Yong Kang. (2016, April 26). RUMMS: THE LATEST FAMILY OF ANDROID MALWARE ATTACKING USERS IN RUSSIA VIA SMS PHISHING. Retrieved February 6, 2017.

    Open source URL
  14. [14]
    fb_arid_viper

    Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.

    Open source URL
  15. [15]
    Trend Micro Bouncing Golf 2019

    E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020.

    Open source URL
  16. [16]
    Talos GPlayed

    V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020.

    Open source URL
  17. [17]
    Cybereason EventBot

    D. Frank, L. Rochberger, Y. Rimmer, A. Dahan. (2020, April 30). EventBot: A New Mobile Banking Trojan is Born. Retrieved June 26, 2020.

    Open source URL
  18. [18]
    Lookout Desert Scorpion

    A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020.

    Open source URL
  19. [19]
    Kaspersky Triada March 2016

    Snow, J. (2016, March 3). Triada: organized crime on Android. Retrieved July 16, 2019.

    Open source URL
  20. [20]
    EnkiWhiteHat_KimsukyDOCSWAP_Dec2025

    EnkiWhiteHat. (2025, December 16). Kimsuky Distributing Malicious Mobile App via QR Code. Retrieved January 8, 2026.

    Open source URL
  21. [21]
    S2W_DocSwap_Mar2025

    Kim, H., S2W TALON. (2025, March 13). Detailed Analysis of DocSwap Malware Disguised as Security Document Viewer. Retrieved January 12, 2026.

    Open source URL
  22. [22]
    nccgroup_sharkbot_0322

    RIFT: Research and Intelligence Fusion Team. (2022, March 3). SharkBot: a “new” generation Android banking Trojan being distributed on Google Play Store. Retrieved January 18, 2023.

    Open source URL
  23. [23]
    SecurityIntelligence TrickMo

    P. Asinovsky. (2020, March 24). TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany. Retrieved April 24, 2020.

    Open source URL
  24. [24]
    Talos Gustuff Apr 2019

    Vitor Ventura. (2019, April 9). Gustuff banking botnet targets Australia . Retrieved September 3, 2019.

    Open source URL
  25. [25]
    Talos-WolfRAT

    W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back... . Retrieved July 20, 2020.

    Open source URL
  26. [26]
    Sophos Red Alert 2.0

    J. Chandraiah. (2018, July 23). Red Alert 2.0: Android Trojan targets security-seekers. Retrieved December 14, 2020.

    Open source URL
  27. [27]
    MerkleScience_Godfather_April2023

    Merkle Science. (2023, April 25). The Godfather Android Malware: Threat under the lens. Retrieved July 16, 2025.

    Open source URL
  28. [28]
    Google Project Zero Insomnia

    I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020.

    Open source URL
  29. [29]
    Threat Fabric Cerberus

    Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020.

    Open source URL
  30. [30]
    lookout_abstractemu_1021

    P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023.

    Open source URL
  31. [31]
    cyble_chameleon_0423

    Cyble Research & Intelligence Labs. (2023, April 13). Banking Trojan targeting mobile users in Australia and Poland. Retrieved August 16, 2023.

    Open source URL
  32. [32]
    McAfee MoqHao 2019

    Pak, C. (2019, August 7). MoqHao Related Android Spyware Targeting Japan and Korea Found on Google Play. Retrieved November 13, 2024.

    Open source URL
  33. [33]
    Kaspersky-WUC

    Costin Raiu, Denis Maslennikov, Kurt Baumgartner. (2013, March 26). Android Trojan Found in Targeted Attack. Retrieved December 23, 2016.

    Open source URL
  34. [34]
    Zscaler TikTok Spyware

    S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021.

    Open source URL
  35. [35]
    Tripwire-MazarBOT

    Graham Cluley. (2016, February 16). Android users warned of malware attack spreading via SMS. Retrieved December 23, 2016.

    Open source URL
  36. [36]
    cloudmark_tanglebot_0921

    Felipe Naves, Andrew Conway, W. Stuart Jones, Adam McNeil . (2021, September 23). TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures. Retrieved February 28, 2023.

    Open source URL
  37. [37]
    Lookout-Pegasus

    Lookout. (2016). Technical Analysis of Pegasus Spyware. Retrieved December 12, 2016.

    Open source URL
  38. [38]
    TrendMicro Coronavirus Updates

    T. Bao, J. Lu. (2020, April 14). Coronavirus Update App Leads to Project Spy Android and iOS Spyware. Retrieved April 24, 2020.

    Open source URL
  39. [39]
    PaloAlto-Xbot

    Cong Zheng, Claud Xiao and Zhi Xu. (2016, February 18). New Android Trojan “Xbot” Phishes Credit Cards and Bank Accounts, Encrypts Devices for Ransom. Retrieved December 21, 2016.

  40. [40]
    TrendMicro-XLoader

    Lorin Wu. (2018, April 19). XLoader Android Spyware and Banking Trojan Distributed via DNS Spoofing. Retrieved July 6, 2018.

    Open source URL
  41. [41]
    Meta Adversarial Threat Report 2022

    Agranovich, D., et al. (2022, April). Adversarial Threat Report. Retrieved April 2, 2024.

    Open source URL
  42. [42]
    cyble_drinik_1022

    Cyble. (2022, October 27). Drinik Malware Returns With Advanced Capabilities Targeting Indian Taxpayers. Retrieved November 17, 2024.

    Open source URL
  43. [43]
    BlackBerry Bahamut

    The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.

    Open source URL
  44. [44]
    Zscaler-SuperMarioRun

    Viral Gandhi. (2017, January 12). Super Mario Run Malware #2 – DroidJack RAT. Retrieved January 20, 2017.

    Open source URL
  45. [45]
    SecureList OpTriangulation 23Oct2023

    Kucherin, G., et al. (2023, October 23). The outstanding stealth of Operation Triangulation. Retrieved April 18, 2024.

    Open source URL
  46. [46]
    Lookout_DCHSpy_July2025

    Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025.

    Open source URL
  47. [47]
    Lookout-EnterpriseApps

    Lookout. (2016, May 25). 5 active mobile threats spoofing enterprise apps. Retrieved December 19, 2016.

    Open source URL
  48. [48]
    forcepoint_bitter

    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved March 1, 2024.

    Open source URL
  49. [49]
    SWB Exodus March 2019

    Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024.

    Open source URL
  50. [50]
    ZimperiumGupta_RatMilad_Oct2022

    Gupta, N. (2022, October 5). We Smell A RatMilad Android Spyware. Retrieved August 27, 2025.

    Open source URL
  51. [51]
    ESET_VajraSpy_Feb2024

    Stefanko, L. (2024, February 1). VajraSpy: A Patchwork of espionage apps. Retrieved October 27, 2025.

    Open source URL
  52. [52]
    K7Dhanalakshmi_VajraSpy_April2022

    Dhanalakshmi. (2022, April 19). VajraSpy – An Android RAT. Retrieved November 5, 2025.

    Open source URL
  53. [53]
    kaspersky_fakecalls_0422

    Igor Golovin. (2022, April 11). Fakecalls: a talking Trojan. Retrieved July 21, 2023.

    Open source URL
  54. [54]
    ThreatFabric_Crocodilus_March2025

    ThreatFabric. (2025, March 28). Exposing Crocodilus: New Device Takeover Malware Targeting Android Devices. Retrieved November 24, 2025.

    Open source URL
  55. [55]
    Symantec GoldenCup

    R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020.

    Open source URL
  56. [56]
    securelist rotexy 2018

    T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019.

    Open source URL
  57. [57]
    Threat Fabric Exobot

    Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020.

    Open source URL
  58. [58]
    Lookout FrozenCell

    Michael Flossman. (2017, October 5). FrozenCell: Multi-platform surveillance campaign against Palestinians. Retrieved November 11, 2020.

    Open source URL
  59. [59]
    Kaspersky Riltok June 2019

    Tatyana Shishkova. (2019, June 25). Riltok mobile Trojan: A banker with global reach. Retrieved August 7, 2019.

    Open source URL
  60. [60]
    SecureList BusyGasper

    Alexey Firsh. (2018, August 29). BusyGasper – the unfriendly spy. Retrieved October 1, 2021.

    Open source URL
  61. [61]
    Cybereason FakeSpy

    O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020.

    Open source URL
  62. [62]
    proofpoint_flubot_0421

    Crista Giering, F. Naves, Andrew Conway, Adam McNeil . (2021, April 27). FluBot Android Malware Spreading Rapidly Through Europe, May Hit U.S. Soon. Retrieved February 28, 2023.

    Open source URL
  63. [63]
    lookout_bouldspy_0423

    Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023.

    Open source URL
  64. [64]
    Lookout Dark Caracal Jan 2018

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

    Open source URL
  65. [65]
    CyberMerchants-FlexiSpy

    Actis B. (2017, April 22). FlexSpy Application Analysis. Retrieved September 4, 2019.

  66. [66]
    FlexiSpy-Features

    FlexiSpy. (n.d.). FlexiSpy Monitoring Features. Retrieved September 4, 2019.

    Open source URL
  67. [67]
    Zscaler-SpyNote

    Shivang Desai. (2017, January 23). SpyNote RAT posing as Netflix app. Retrieved January 26, 2017.

    Open source URL
  68. [68]
    welivesecurity_apt-c-23

    Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.

    Open source URL
  69. [69]
    sophos_android_apt_spyware

    Kohli, P. (2021, November 23). Android APT spyware, targeting Middle East victims, enhances evasiveness. Retrieved November 17, 2024.

    Open source URL
  70. [70]
    threatpost AndroidSpyware 2020

    O'Donnell, L. (2020, September 30). Android Spyware Variant Snoops on WhatsApp, Telegram Messages. Retrieved January 10, 2025.

    Open source URL
  71. [71]
    Securelist Asacub

    T. Shishkova. (2018, August 28). The rise of mobile banker Asacub. Retrieved December 14, 2020.

    Open source URL
  72. [72]
    MelikovBlackBerry LightSpy 2024

    Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025.

    Open source URL
  73. [73]
    Threatfabric LightSpy 2023

    ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025.

    Open source URL
  74. [74]
    Threatfabric LightSpy 2024

    ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025.

    Open source URL
  75. [75]
    LinkedIn Dmitry LightSpy 2025

    Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy's iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025.

    Open source URL
  76. [76]
    PaloAlto-SpyDealer

    Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018.

    Open source URL
  77. [77]
    Cylance Dust Storm

    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

    Open source URL
  78. [78]
    Lookout ViperRAT

    M. Flossman. (2017, February 16). ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar. Retrieved September 11, 2020.

    Open source URL
  79. [79]
    Bitdefender Mandrake

    R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020.

    Open source URL
  80. [80]
    NIST Mobile Threat CatalogueAPP-13
    Open source URL
  81. [81]
    NIST Mobile Threat CatalogueAPP-13
    Open source URL
  82. [82]
    mitre-attackT1636.004
    Open source URL
  83. [83]
    mitre-attackT1636.004
    Open source URL
  84. [84]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  85. [85]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  86. [86]
    Lookout Uyghur Campaign

    A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020.

    Open source URL
  87. [87]
    Lookout Dark Caracal Jan 2018

    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

    Open source URL
  88. [88]
    Lookout-StealthMango

    Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.