# T1404 Exploitation for Privilege Escalation

> As of 2026-10-05, T1404 (Exploitation for Privilege Escalation) appears in 17 tracked threats, first reported 2026-04-10 and most recently 2026-09-27, with linked actors including Intellexa Consortium, NSO Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 17 (5 critical, 10 high, 1 medium)
- **First seen:** 2026-04-10
- **Last seen:** 2026-09-27
- **Threat actors:** 2
- **Detection rules:** 39 (counts only; Blue tier and above)

## Key facts

- **ID:** T1404
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1404/

## Activity timeline

T1404 first appeared in tracked threats on 2026-04-10 and was most recently reported on 2026-09-27. The busiest month was 2026-09 with 6 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1404 Exploitation for Privilege Escalation is catalogued by MITRE ATT&CK under the Privilege Escalation (Mobile) tactic in the Mobile matrix. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 10 high, 1 medium.

Threats that use T1404 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (11 threats), [T1430 Location Tracking](https://intel.threadlinqs.com/technique/T1430) (11 threats), [T1409 Stored Application Data](https://intel.threadlinqs.com/technique/T1409) (9 threats), [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (9 threats), [T1512 Video Capture](https://intel.threadlinqs.com/technique/T1512) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1404; the most frequent are [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (2), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (2).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1404.

- [M1001 Security Updates](https://attack.mitre.org/mitigations/M1001/)
- [M1002 Attestation](https://attack.mitre.org/mitigations/M1002/)
- [M1010 Deploy Compromised Device Detection Method](https://attack.mitre.org/mitigations/M1010/)

## Threat actors using it

- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 2
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 2

## Tracked threats

17 tracked threats use T1404.

- [Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…](https://intel.threadlinqs.com/threat/TL-2026-2683) — high — 2026-09-27
- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — critical — 2026-09-20
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — critical — 2026-09-18
- [Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…](https://intel.threadlinqs.com/threat/TL-2026-2418) — critical — 2026-09-09
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — high — 2026-09-04
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight](https://intel.threadlinqs.com/threat/TL-2026-2118) — high — 2026-08-22
- [Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Images](https://intel.threadlinqs.com/threat/TL-2026-2060) — high — 2026-08-18
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…](https://intel.threadlinqs.com/threat/TL-2026-1726) — medium — 2026-07-27
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [CVE-2026-20971: Eight-Year-Old Samsung Knox PROCA/FIVE Kernel Use-After-Free in /proc/pid/integrity Handlers](https://intel.threadlinqs.com/threat/TL-2026-0925) — high — 2026-06-24
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [Predator Spyware: Undocumented iOS Kernel Exploitation Engine (FDGuardNeonRW, PAC Bypass, RWTransfer)](https://intel.threadlinqs.com/threat/TL-2026-2046) — high — 2026-04-10

## Related CVEs

CVEs referenced by the tracked threats that use T1404, most frequent first.

- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2025-54957](https://intel.threadlinqs.com/cve/CVE-2025-54957)
- [CVE-2026-20971](https://intel.threadlinqs.com/cve/CVE-2026-20971)

## Detection coverage

Threadlinqs maintains 39 detection rules mapped to T1404 (SPL 17, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

39 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1404
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
