Activity timeline
T1418 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 34 of the 34 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1418 Software Discovery is catalogued by MITRE ATT&CK under the Discovery (Mobile) tactic in the Mobile matrix. Threadlinqs maps 34 of 2623 tracked threats (1.3%) to it; by severity that is 3 critical, 28 high, 2 medium.
Threats that use T1418 most often also use T1660 Phishing (29 threats), T1513 Screen Capture (23 threats), T1646 Exfiltration Over C2 Channel (21 threats), T1426 System Information Discovery (19 threats), T1437 Application Layer Protocol (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1418; the most frequent are NSO Group (2), Cyber Av3ngers (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1418.
Threat actors using it
Tracked threats
The 30 most recent of 34 tracked threats that use T1418.
- Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…high
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV Apphigh
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryptioncritical
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)high
- Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integrationhigh
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…high
- Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…high
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europehigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…medium
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…high
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutionshigh
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Accesshigh
- Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…high
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commandshigh
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…high
- Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…medium
- FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…high
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…high
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…critical
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…high
Detection coverage
Threadlinqs maintains 30 detection rules mapped to T1418 (SPL 8, KQL 11, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1418.001 Security Software Discovery — 2 tracked threats