Activity timeline
T1629 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 7 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1629 Impair Defenses is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 10 high, 2 medium.
Threats that use T1629 most often also use T1418 Software Discovery (10 threats), T1417 Input Capture (9 threats), T1437 Application Layer Protocol (9 threats), T1513 Screen Capture (9 threats), T1655 Masquerading (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
Mitigations
MITRE ATT&CK lists 5 mitigations for T1629.
Tracked threats
14 tracked threats use T1629.
- Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…high
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV Apphigh
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokhigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Adsmedium
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…medium
- RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Accesshigh
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committeecritical
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commandshigh
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…high
Detection coverage
Threadlinqs maintains 15 detection rules mapped to T1629 (SPL 5, KQL 4, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1629.001 Prevent Application Removal — 5 tracked threats
- T1629.002 Device Lockout — 3 tracked threats
- T1629.003 Disable or Modify Tools — 4 tracked threats