Activity timeline
T1417.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 5 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1417.001 Keylogging is catalogued by MITRE ATT&CK under the Collection (Mobile) and Credential Access (Mobile) tactics in the Mobile matrix, as a sub-technique of T1417 Input Capture. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 1 critical, 11 high.
Threats that use T1417.001 most often also use T1513 Screen Capture (10 threats), T1660 Phishing (10 threats), T1417.002 GUI Input Capture (9 threats), T1418 Software Discovery (8 threats), T1516 Input Injection (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1417.001; the most frequent are Balonx (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1417.001.
Threat actors using it
Tracked threats
12 tracked threats use T1417.001.
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritizationhigh
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV Apphigh
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)high
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokhigh
- Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…high
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote…high
- ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…high
Detection coverage
Threadlinqs maintains 35 detection rules mapped to T1417.001 (SPL 12, KQL 14, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1417 Input Capture — 31 tracked threats at the technique level.