Activity timeline
T1430 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 31 of the 31 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1430 Location Tracking is catalogued by MITRE ATT&CK under the Collection (Mobile) and Discovery (Mobile) tactics in the Mobile matrix. Threadlinqs maps 31 of 2623 tracked threats (1.2%) to it; by severity that is 4 critical, 23 high, 3 medium.
Threats that use T1430 most often also use T1429 Audio Capture (20 threats), T1426 System Information Discovery (17 threats), T1660 Phishing (17 threats), T1646 Exfiltration Over C2 Channel (16 threats), T1636 Protected User Data (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1430; the most frequent are NSO Group (3), APT37 (1), GreyVibe (1), Intellexa Consortium (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1430.
Threat actors using it
Tracked threats
The 30 most recent of 31 tracked threats that use T1430.
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…medium
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnelhigh
- Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integrationhigh
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Memberhigh
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…high
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Imageshigh
- Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countrieshigh
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targetshigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…
- Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026high
- UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…medium
- Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…high
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutionshigh
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committeecritical
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…critical
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…high
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…high
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)high
- GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs &…high
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…high
- ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn…high
- Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Usershigh
- Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious…medium
- SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolutionhigh
- ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…high
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1430 (SPL 6, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1430.001 Remote Device Management Services — 0 tracked threats
- T1430.002 Impersonate SS7 Nodes — 2 tracked threats