# T1417.002 GUI Input Capture

> As of 2026-10-05, T1417.002 (GUI Input Capture) appears in 18 tracked threats, first reported 2026-02-16 and most recently 2026-09-28, with linked actors including Cyber Av3ngers, Interlock, SHADOW-EARTH-053; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 18 (1 critical, 17 high)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-28
- **Threat actors:** 3
- **Detection rules:** 44 (counts only; Blue tier and above)

## Key facts

- **ID:** T1417.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access (Mobile), Collection (Mobile)
- **Matrix:** Mobile
- **Parent:** T1417
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1417/002/

## Activity timeline

T1417.002 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-28. The busiest month was 2026-09 with 7 reports, and 18 of the 18 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1417.002 GUI Input Capture is catalogued by MITRE ATT&CK under the Credential Access (Mobile) and Collection (Mobile) tactics in the Mobile matrix, as a sub-technique of [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417). Threadlinqs maps 18 of 2623 tracked threats (0.7%) to it; by severity that is 1 critical, 17 high.

Threats that use T1417.002 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (15 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (14 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (14 threats), [T1516 Input Injection](https://intel.threadlinqs.com/technique/T1516) (12 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1417.002; the most frequent are [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1), [Interlock](https://intel.threadlinqs.com/actor/Interlock) (1), [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1417.002.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)
- [M1012 Enterprise Policy](https://attack.mitre.org/mitigations/M1012/)

## Threat actors using it

- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 1
- [SHADOW-EARTH-053](https://intel.threadlinqs.com/actor/SHADOW-EARTH-053) — 1

## Tracked threats

18 tracked threats use T1417.002.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)](https://intel.threadlinqs.com/threat/TL-2026-2444) — high — 2026-09-11
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum…](https://intel.threadlinqs.com/threat/TL-2026-2310) — high — 2026-09-03
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight](https://intel.threadlinqs.com/threat/TL-2026-2118) — high — 2026-08-22
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…](https://intel.threadlinqs.com/threat/TL-2026-1659) — high — 2026-07-23
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Access](https://intel.threadlinqs.com/threat/TL-2026-1248) — high — 2026-07-12
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote…](https://intel.threadlinqs.com/threat/TL-2026-0135) — high — 2026-02-23
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1417.002, most frequent first.

- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-4345](https://intel.threadlinqs.com/cve/CVE-2024-4345)
- [CVE-2025-68947](https://intel.threadlinqs.com/cve/CVE-2025-68947)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)

## Detection coverage

Threadlinqs maintains 44 detection rules mapped to T1417.002 (SPL 15, KQL 17, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

44 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) — 31 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1417.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
