# T1422 System Network Configuration Discovery

> As of 2026-10-05, T1422 (System Network Configuration Discovery) appears in 12 tracked threats, first reported 2026-02-24 and most recently 2026-09-03, with linked actors including MoYu Group, APT37, NSO Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 12 (10 high, 1 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-03
- **Threat actors:** 3
- **Detection rules:** 6 (counts only; Blue tier and above)

## Key facts

- **ID:** T1422
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1422/

## Activity timeline

T1422 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-03. The busiest month was 2026-08 with 4 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1422 System Network Configuration Discovery is catalogued by MITRE ATT&CK under the Discovery (Mobile) tactic in the Mobile matrix. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 10 high, 1 medium.

Threats that use T1422 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (11 threats), [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (8 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (8 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (8 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1422; the most frequent are [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (2), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1422.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)

## Threat actors using it

- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

12 tracked threats use T1422.

- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — high — 2026-08-25
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…](https://intel.threadlinqs.com/threat/TL-2026-0143) — high — 2026-02-25
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24

## Related CVEs

CVEs referenced by the tracked threats that use T1422, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)

## Detection coverage

Threadlinqs maintains 6 detection rules mapped to T1422 (SPL 1, KQL 2, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

6 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1422.001 Internet Connection Discovery — 1 tracked threat
- T1422.002 Wi-Fi Discovery — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1422
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
