# T1629 Impair Defenses

> As of 2026-10-05, T1629 (Impair Defenses) appears in 14 tracked threats, first reported 2026-05-11 and most recently 2026-09-27; it most often appears alongside T1418 (Software Discovery).

- **Tracked threats:** 14 (2 critical, 10 high, 2 medium)
- **First seen:** 2026-05-11
- **Last seen:** 2026-09-27
- **Detection rules:** 15 (counts only; Blue tier and above)

## Key facts

- **ID:** T1629
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1629/

## Activity timeline

T1629 first appeared in tracked threats on 2026-05-11 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 7 reports, and 14 of the 14 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1629 Impair Defenses is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 10 high, 2 medium.

Threats that use T1629 most often also use [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (10 threats), [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (9 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (9 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (9 threats), [T1655 Masquerading](https://intel.threadlinqs.com/technique/T1655) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1629.

- [M1001 Security Updates](https://attack.mitre.org/mitigations/M1001/)
- [M1004 System Partition Integrity](https://attack.mitre.org/mitigations/M1004/)
- [M1010 Deploy Compromised Device Detection Method](https://attack.mitre.org/mitigations/M1010/)
- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)
- [M1012 Enterprise Policy](https://attack.mitre.org/mitigations/M1012/)

## Tracked threats

14 tracked threats use T1629.

- [Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via…](https://intel.threadlinqs.com/threat/TL-2026-2683) — high — 2026-09-27
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads](https://intel.threadlinqs.com/threat/TL-2026-1724) — medium — 2026-07-27
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- [RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Access](https://intel.threadlinqs.com/threat/TL-2026-1248) — high — 2026-07-12
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11

## Detection coverage

Threadlinqs maintains 15 detection rules mapped to T1629 (SPL 5, KQL 4, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

15 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1629.001 Prevent Application Removal — 5 tracked threats
- T1629.002 Device Lockout — 3 tracked threats
- T1629.003 Disable or Modify Tools — 4 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1629
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
