# T1655.001 Match Legitimate Name or Location

> As of 2026-10-10, T1655.001 (Match Legitimate Name or Location) appears in 12 tracked threats, first reported 2026-02-16 and most recently 2026-10-09; it most often appears alongside T1418 (Software Discovery).

- **Tracked threats:** 12 (1 critical, 10 high, 1 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-09
- **Detection rules:** 41 (counts only; Blue tier and above)

## Key facts

- **ID:** T1655.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile)
- **Matrix:** Mobile
- **Parent:** T1655
- **Data as of:** 2026-10-10
- **MITRE:** https://attack.mitre.org/techniques/T1655/001/

## Activity timeline

T1655.001 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-09. The busiest month was 2026-09 with 4 reports, and 12 of the 12 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1655.001 Match Legitimate Name or Location is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix, as a sub-technique of [T1655 Masquerading](https://intel.threadlinqs.com/technique/T1655). Threadlinqs maps 12 of 2756 tracked threats (0.4%) to it; by severity that is 1 critical, 10 high, 1 medium.

Threats that use T1655.001 most often also use [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (10 threats), [T1417.002 GUI Input Capture](https://intel.threadlinqs.com/technique/T1417.002) (9 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (9 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (8 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1655.001.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Tracked threats

12 tracked threats use T1655.001.

- [Novinarya: Android stealer hiding its live C2 in a basalam.com shop profile bio](https://intel.threadlinqs.com/threat/TL-2026-3128) — high — 2026-10-09
- [Malicious PDF Reader on Google Play (10,000+ installs) Delivers Anatsa (TeaBot) Banking Trojan](https://intel.threadlinqs.com/threat/TL-2026-3099) — high — 2026-10-09
- [Midnight Mimosa: Low-cost MediaTek Android phones ship with firmware-level ad-fraud and residential proxy…](https://intel.threadlinqs.com/threat/TL-2026-3066) — high — 2026-10-09
- [Crypter-as-a-Service Obfuscation Enabling Undetectable Android/Mobile Malware (ASD-led Advisory "Digital…](https://intel.threadlinqs.com/threat/TL-2026-3033) — high — 2026-10-07
- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads…](https://intel.threadlinqs.com/threat/TL-2026-2279) — high — 2026-09-01
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Detection coverage

Threadlinqs maintains 41 detection rules mapped to T1655.001 (SPL 19, KQL 9, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

41 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1655 Masquerading](https://intel.threadlinqs.com/technique/T1655) — 23 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1655.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
