# T1626 Abuse Elevation Control Mechanism

> As of 2026-10-05, T1626 (Abuse Elevation Control Mechanism) appears in 14 tracked threats, first reported 2026-05-11 and most recently 2026-09-28; it most often appears alongside T1513 (Screen Capture).

- **Tracked threats:** 14 (2 critical, 11 high, 1 medium)
- **First seen:** 2026-05-11
- **Last seen:** 2026-09-28
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1626
- **Framework:** MITRE ATT&CK
- **Tactics:** Privilege Escalation (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1626/

## Activity timeline

T1626 first appeared in tracked threats on 2026-05-11 and was most recently reported on 2026-09-28. The busiest month was 2026-09 with 5 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1626 Abuse Elevation Control Mechanism is catalogued by MITRE ATT&CK under the Privilege Escalation (Mobile) tactic in the Mobile matrix. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 11 high, 1 medium.

Threats that use T1626 most often also use [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (12 threats), [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (10 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (10 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (10 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1626.

- [M1013 Application Developer Guidance](https://attack.mitre.org/mitigations/M1013/)

## Tracked threats

14 tracked threats use T1626.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)](https://intel.threadlinqs.com/threat/TL-2026-2444) — high — 2026-09-11
- [Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…](https://intel.threadlinqs.com/threat/TL-2026-2418) — critical — 2026-09-09
- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…](https://intel.threadlinqs.com/threat/TL-2026-2279) — high — 2026-09-01
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11

## Related CVEs

CVEs referenced by the tracked threats that use T1626, most frequent first.

- [CVE-2025-54957](https://intel.threadlinqs.com/cve/CVE-2025-54957)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1626 (SPL 12, KQL 8, Sigma 9). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1626.001 Device Administrator Permissions — 5 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1626
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
