# T1630 Indicator Removal on Host

> As of 2026-10-05, T1630 (Indicator Removal on Host) appears in 11 tracked threats, first reported 2026-03-07 and most recently 2026-09-03, with linked actors including Intellexa Consortium, NSO Group; it most often appears alongside T1417 (Input Capture).

- **Tracked threats:** 11 (10 high, 1 low)
- **First seen:** 2026-03-07
- **Last seen:** 2026-09-03
- **Threat actors:** 2
- **Detection rules:** 15 (counts only; Blue tier and above)

## Key facts

- **ID:** T1630
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1630/

## Activity timeline

T1630 first appeared in tracked threats on 2026-03-07 and was most recently reported on 2026-09-03. The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1630 Indicator Removal on Host is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 10 high, 1 low.

Threats that use T1630 most often also use [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (9 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (9 threats), [T1636 Protected User Data](https://intel.threadlinqs.com/technique/T1636) (9 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (8 threats), [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1630; the most frequent are [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (2), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (2).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1630.

- [M1001 Security Updates](https://attack.mitre.org/mitigations/M1001/)
- [M1002 Attestation](https://attack.mitre.org/mitigations/M1002/)
- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 2
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 2

## Tracked threats

11 tracked threats use T1630.

- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…](https://intel.threadlinqs.com/threat/TL-2026-1753) — low — 2026-07-29
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0728) — high — 2026-06-09
- [Predator Spyware: Undocumented iOS Kernel Exploitation Engine (FDGuardNeonRW, PAC Bypass, RWTransfer)](https://intel.threadlinqs.com/threat/TL-2026-2046) — high — 2026-04-10
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07

## Related CVEs

CVEs referenced by the tracked threats that use T1630, most frequent first.

- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2019-3568](https://intel.threadlinqs.com/cve/CVE-2019-3568)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)

## Detection coverage

Threadlinqs maintains 15 detection rules mapped to T1630 (SPL 4, KQL 5, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

15 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1630.001 Uninstall Malicious Application — 1 tracked threat
- T1630.002 File Deletion — 3 tracked threats
- T1630.003 Disguise Root/Jailbreak Indicators — 1 tracked threat

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1630
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
