Domain | ID | Name | Use | |
---|---|---|---|---|
Mobile | T1640 | Account Access Removal | ||
Mobile | T1638 | Adversary-in-the-Middle |
Monokle can install attacker-specified certificates to the device's trusted certificate store, enabling an adversary to perform adversary-in-the-middle attacks.[2] |
|
Mobile | T1429 | Audio Capture |
Monokle can record audio from the device's microphone and can record phone calls, specifying the output audio quality.[1] |
|
Mobile | T1616 | Call Control |
Monokle can be controlled via phone call from a set of "control phones."[1] |
|
Mobile | T1645 | Compromise Client Software Binary |
Monokle can remount the system partition as read/write to install attacker-specified certificates.[1] |
|
Mobile | T1533 | Data from Local System |
Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash. Monokle can also capture the user’s dictionary, user-defined shortcuts, and browser history, enabling profiling of the user and their activities.[1] |
|
Mobile | T1617 | Hooking |
Monokle can hook itself to appear invisible to the Process Manager.[1] |
|
Mobile | T1630 | .002 | Indicator Removal on Host: File Deletion |
Monokle can delete arbitrary files on the device, and can also uninstall itself and clean up staging files.[1] |
Mobile | T1544 | Ingress Tool Transfer | ||
Mobile | T1417 | .001 | Input Capture: Keylogging | |
Mobile | T1430 | Location Tracking | ||
Mobile | T1406 | Obfuscated Files or Information | ||
Mobile | T1644 | Out of Band Data |
Monokle can be controlled via email and SMS from a set of "control phones."[1] |
|
Mobile | T1636 | .001 | Protected User Data: Calendar Entries |
Monokle can retrieve calendar event information including the event name, when and where it is taking place, and the description.[1] |
.002 | Protected User Data: Call Log | |||
.003 | Protected User Data: Contact List | |||
Mobile | T1513 | Screen Capture |
Monokle can record the screen as the user unlocks the device and can take screenshots of any application in the foreground. Monokle can also abuse accessibility features to read the screen to capture data from a large number of popular applications.[1] |
|
Mobile | T1418 | Software Discovery | ||
Mobile | T1426 | System Information Discovery |
Monokle queries the device for metadata such as make, model, and power levels.[1] |
|
Mobile | T1422 | System Network Configuration Discovery |
Monokle checks if the device is connected via Wi-Fi or mobile data.[1] |
|
.001 | Internet Connection Discovery |
Monokle checks if the device is connected via Wi-Fi or mobile data.[1] |
||
.002 | Wi-Fi Discovery |
Monokle checks if the device is connected via Wi-Fi or mobile data.[1] |
||
Mobile | T1421 | System Network Connections Discovery |
Monokle can retrieve nearby cell tower and Wi-Fi network information.[1] |
|
Mobile | T1512 | Video Capture |