Activity timeline
T1626 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-09 with 5 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1626 Abuse Elevation Control Mechanism is catalogued by MITRE ATT&CK under the Privilege Escalation (Mobile) tactic in the Mobile matrix. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 11 high, 1 medium.
Threats that use T1626 most often also use T1513 Screen Capture (12 threats), T1417 Input Capture (10 threats), T1541 Foreground Persistence (10 threats), T1660 Phishing (10 threats), T1418 Software Discovery (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
Mitigations
MITRE ATT&CK lists 1 mitigation for T1626.
Tracked threats
14 tracked threats use T1626.
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritizationhigh
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)high
- Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…critical
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokhigh
- Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…high
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…high
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…medium
- Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…high
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commandshigh
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…high
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…high
Detection coverage
Threadlinqs maintains 29 detection rules mapped to T1626 (SPL 12, KQL 8, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1626.001 Device Administrator Permissions — 5 tracked threats