# T1430 Location Tracking

> As of 2026-10-05, T1430 (Location Tracking) appears in 31 tracked threats, first reported 2026-02-12 and most recently 2026-09-28, with linked actors including NSO Group, APT37, GreyVibe; it most often appears alongside T1429 (Audio Capture).

- **Tracked threats:** 31 (4 critical, 23 high, 3 medium)
- **First seen:** 2026-02-12
- **Last seen:** 2026-09-28
- **Threat actors:** 4
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1430
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile), Discovery (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1430/

## Activity timeline

T1430 first appeared in tracked threats on 2026-02-12 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 10 reports, and 31 of the 31 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1430 Location Tracking is catalogued by MITRE ATT&CK under the Collection (Mobile) and Discovery (Mobile) tactics in the Mobile matrix. Threadlinqs maps 31 of 2623 tracked threats (1.2%) to it; by severity that is 4 critical, 23 high, 3 medium.

Threats that use T1430 most often also use [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (20 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (17 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (17 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (16 threats), [T1636 Protected User Data](https://intel.threadlinqs.com/technique/T1636) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1430; the most frequent are [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (3), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe) (1), [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1430.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)
- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)
- [M1012 Enterprise Policy](https://attack.mitre.org/mitigations/M1012/)
- [M1014 Interconnection Filtering](https://attack.mitre.org/mitigations/M1014/)

## Threat actors using it

- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 3
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1

## Tracked threats

The 30 most recent of 31 tracked threats that use T1430.

- [GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…](https://intel.threadlinqs.com/threat/TL-2026-2744) — medium — 2026-09-28
- [Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel](https://intel.threadlinqs.com/threat/TL-2026-2609) — high — 2026-09-21
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — high — 2026-09-04
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight](https://intel.threadlinqs.com/threat/TL-2026-2118) — high — 2026-08-22
- [Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious Images](https://intel.threadlinqs.com/threat/TL-2026-2060) — high — 2026-08-18
- [Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries](https://intel.threadlinqs.com/threat/TL-2026-2034) — high — 2026-08-16
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026](https://intel.threadlinqs.com/threat/TL-2026-1737) — high — 2026-07-28
- [UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case…](https://intel.threadlinqs.com/threat/TL-2026-1726) — medium — 2026-07-27
- [Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…](https://intel.threadlinqs.com/threat/TL-2026-1673) — high — 2026-07-24
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0728) — high — 2026-06-09
- [GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs &…](https://intel.threadlinqs.com/threat/TL-2026-0622) — high — 2026-05-28
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07
- [Large-Scale Scam and Impersonation Campaign Targeting Commercial Airline Industry (11,600+ Malicious…](https://intel.threadlinqs.com/threat/TL-2026-1524) — medium — 2026-02-24
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1430, most frequent first.

- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2025-43529](https://intel.threadlinqs.com/cve/CVE-2025-43529)
- [CVE-2026-20700](https://intel.threadlinqs.com/cve/CVE-2026-20700)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1430 (SPL 6, KQL 11, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1430.001 Remote Device Management Services — 0 tracked threats
- T1430.002 Impersonate SS7 Nodes — 2 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1430
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
