# T1418 Software Discovery

> As of 2026-10-05, T1418 (Software Discovery) appears in 34 tracked threats, first reported 2026-02-16 and most recently 2026-09-27, with linked actors including NSO Group, Cyber Av3ngers; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 34 (3 critical, 28 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-27
- **Threat actors:** 2
- **Detection rules:** 30 (counts only; Blue tier and above)

## Key facts

- **ID:** T1418
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1418/

## Activity timeline

T1418 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 10 reports, and 34 of the 34 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1418 Software Discovery is catalogued by MITRE ATT&CK under the Discovery (Mobile) tactic in the Mobile matrix. Threadlinqs maps 34 of 2623 tracked threats (1.3%) to it; by severity that is 3 critical, 28 high, 2 medium.

Threats that use T1418 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (29 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (23 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (21 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (19 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (19 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1418; the most frequent are [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (2), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1418.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)
- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 2
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1

## Tracked threats

The 30 most recent of 34 tracked threats that use T1418.

- [Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…](https://intel.threadlinqs.com/threat/TL-2026-2683) — high — 2026-09-27
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — critical — 2026-09-20
- [Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)](https://intel.threadlinqs.com/threat/TL-2026-2444) — high — 2026-09-11
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…](https://intel.threadlinqs.com/threat/TL-2026-2279) — high — 2026-09-01
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe](https://intel.threadlinqs.com/threat/TL-2026-1995) — high — 2026-08-12
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…](https://intel.threadlinqs.com/threat/TL-2026-1659) — high — 2026-07-23
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…](https://intel.threadlinqs.com/threat/TL-2026-1313) — high — 2026-07-14
- [RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Access](https://intel.threadlinqs.com/threat/TL-2026-1248) — high — 2026-07-12
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…](https://intel.threadlinqs.com/threat/TL-2026-0671) — high — 2026-06-03
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11

## Related CVEs

CVEs referenced by the tracked threats that use T1418, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)

## Detection coverage

Threadlinqs maintains 30 detection rules mapped to T1418 (SPL 8, KQL 11, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

30 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1418.001 Security Software Discovery — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1418
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
