# T1582 SMS Control

> As of 2026-10-05, T1582 (SMS Control) appears in 10 tracked threats, first reported 2026-05-11 and most recently 2026-09-09, with linked actors including Cyber Av3ngers; it most often appears alongside T1418 (Software Discovery).

- **Tracked threats:** 10 (10 high)
- **First seen:** 2026-05-11
- **Last seen:** 2026-09-09
- **Threat actors:** 1
- **Detection rules:** 9 (counts only; Blue tier and above)

## Key facts

- **ID:** T1582
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1582/

## Activity timeline

T1582 first appeared in tracked threats on 2026-05-11 and was most recently reported on 2026-09-09. The busiest month was 2026-07 with 5 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1582 SMS Control is catalogued by MITRE ATT&CK under the Impact (Mobile) tactic in the Mobile matrix. Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 10 high.

Threats that use T1582 most often also use [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (10 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (9 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (9 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (8 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1582; the most frequent are [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1582.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1

## Tracked threats

10 tracked threats use T1582.

- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…](https://intel.threadlinqs.com/threat/TL-2026-1659) — high — 2026-07-23
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…](https://intel.threadlinqs.com/threat/TL-2026-1313) — high — 2026-07-14
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11

## Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1582 (SPL 1, KQL 4, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1582
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
