# T1517 Access Notifications

> As of 2026-10-05, T1517 (Access Notifications) appears in 20 tracked threats, first reported 2026-02-16 and most recently 2026-09-28, with linked actors including APT44, NSO Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 20 (2 critical, 16 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-28
- **Threat actors:** 2
- **Detection rules:** 20 (counts only; Blue tier and above)

## Key facts

- **ID:** T1517
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile), Credential Access (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1517/

## Activity timeline

T1517 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 9 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1517 Access Notifications is catalogued by MITRE ATT&CK under the Collection (Mobile) and Credential Access (Mobile) tactics in the Mobile matrix. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 2 critical, 16 high, 2 medium.

Threats that use T1517 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (15 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (15 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (14 threats), [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (13 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1517; the most frequent are [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1517.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)
- [M1012 Enterprise Policy](https://attack.mitre.org/mitigations/M1012/)
- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)

## Threat actors using it

- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

20 tracked threats use T1517.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — medium — 2026-09-25
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage…](https://intel.threadlinqs.com/threat/TL-2026-1527) — high — 2026-07-19
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11
- [ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…](https://intel.threadlinqs.com/threat/TL-2026-0143) — high — 2026-02-25
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1517, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)

## Detection coverage

Threadlinqs maintains 20 detection rules mapped to T1517 (SPL 6, KQL 7, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

20 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1517
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
