# T1453 Abuse Accessibility Features

> As of 2026-10-05, T1453 (Abuse Accessibility Features) appears in 10 tracked threats, first reported 2026-05-27 and most recently 2026-09-28; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 10 (1 critical, 9 high)
- **First seen:** 2026-05-27
- **Last seen:** 2026-09-28
- **Detection rules:** 16 (counts only; Blue tier and above)

## Key facts

- **ID:** T1453
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile), Credential Access (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1453/

## Activity timeline

T1453 first appeared in tracked threats on 2026-05-27 and was most recently reported on 2026-09-28. The busiest month was 2026-09 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1453 Abuse Accessibility Features is catalogued by MITRE ATT&CK under the Collection (Mobile) and Credential Access (Mobile) tactics in the Mobile matrix. Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 9 high.

Threats that use T1453 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (10 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (9 threats), [T1516 Input Injection](https://intel.threadlinqs.com/technique/T1516) (8 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (7 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1453.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Tracked threats

10 tracked threats use T1453.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe](https://intel.threadlinqs.com/threat/TL-2026-1995) — high — 2026-08-12
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27

## Related CVEs

CVEs referenced by the tracked threats that use T1453, most frequent first.

- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)

## Detection coverage

Threadlinqs maintains 16 detection rules mapped to T1453 (SPL 7, KQL 4, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

16 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1453
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
