# T1575 Native API

> As of 2026-10-05, T1575 (Native API) appears in 14 tracked threats, first reported 2026-02-23 and most recently 2026-09-27, with linked actors including NSO Group; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 14 (3 critical, 9 high, 1 medium, 1 low)
- **First seen:** 2026-02-23
- **Last seen:** 2026-09-27
- **Threat actors:** 1
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1575
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile), Execution (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1575/

## Activity timeline

T1575 first appeared in tracked threats on 2026-02-23 and was most recently reported on 2026-09-27. The busiest month was 2026-05 with 3 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1575 Native API is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) and Execution (Mobile) tactics in the Mobile matrix. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 9 high, 1 medium, 1 low.

Threats that use T1575 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (11 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (10 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (9 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (8 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1575; the most frequent are [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Threat actors using it

- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

14 tracked threats use T1575.

- [Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…](https://intel.threadlinqs.com/threat/TL-2026-2683) — high — 2026-09-27
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…](https://intel.threadlinqs.com/threat/TL-2026-2418) — critical — 2026-09-09
- [Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…](https://intel.threadlinqs.com/threat/TL-2026-1753) — low — 2026-07-29
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…](https://intel.threadlinqs.com/threat/TL-2026-0671) — high — 2026-06-03
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11
- [NGate Android Malware — HandyPay-Trojanized NFC Relay Variant Targets Brazilian Cardholders via Fake Rio de…](https://intel.threadlinqs.com/threat/TL-2026-0401) — high — 2026-04-21
- [FakeWallet iOS Crypto Stealer Campaign Delivered Through 26 Apple App Store Apps (SparkKitty-linked…](https://intel.threadlinqs.com/threat/TL-2026-0395) — critical — 2026-04-20
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24
- [PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote…](https://intel.threadlinqs.com/threat/TL-2026-0135) — high — 2026-02-23

## Related CVEs

CVEs referenced by the tracked threats that use T1575, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2025-54957](https://intel.threadlinqs.com/cve/CVE-2025-54957)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1575 (SPL 5, KQL 7, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1575
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
