# T1420 File and Directory Discovery

> As of 2026-10-05, T1420 (File and Directory Discovery) appears in 13 tracked threats, first reported 2026-02-24 and most recently 2026-09-20, with linked actors including APT37, Intellexa Consortium; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 13 (3 critical, 10 high)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-20
- **Threat actors:** 2
- **Detection rules:** 12 (counts only; Blue tier and above)

## Key facts

- **ID:** T1420
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1420/

## Activity timeline

T1420 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-20. The busiest month was 2026-07 with 4 reports, and 13 of the 13 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1420 File and Directory Discovery is catalogued by MITRE ATT&CK under the Discovery (Mobile) tactic in the Mobile matrix. Threadlinqs maps 13 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 10 high.

Threats that use T1420 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (11 threats), [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (9 threats), [T1430 Location Tracking](https://intel.threadlinqs.com/technique/T1430) (9 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (9 threats), [T1414 Clipboard Data](https://intel.threadlinqs.com/technique/T1414) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1420; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1420.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1

## Tracked threats

13 tracked threats use T1420.

- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — critical — 2026-09-20
- [Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)](https://intel.threadlinqs.com/threat/TL-2026-2444) — high — 2026-09-11
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Images](https://intel.threadlinqs.com/threat/TL-2026-2060) — high — 2026-08-18
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [Predator Spyware: Undocumented iOS Kernel Exploitation Engine (FDGuardNeonRW, PAC Bypass, RWTransfer)](https://intel.threadlinqs.com/threat/TL-2026-2046) — high — 2026-04-10
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24

## Related CVEs

CVEs referenced by the tracked threats that use T1420, most frequent first.

- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)

## Detection coverage

Threadlinqs maintains 12 detection rules mapped to T1420 (SPL 3, KQL 2, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

12 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1420
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
