ID | Name |
---|---|
T1418.001 | Security Software Discovery |
Adversaries may attempt to get a listing of applications that are installed on a device. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not to fully infect the target and/or attempts specific actions.
Adversaries may attempt to enumerate applications for a variety of reasons, such as figuring out what security measures are present or to identify the presence of target applications.
ID | Name | Description |
---|---|---|
S1061 | AbstractEmu |
AbstractEmu can obtain a list of installed applications.[1] |
S0440 | Agent Smith |
Agent Smith obtains the device’s application list.[2] |
S0525 | Android/AdDisplay.Ashas |
Android/AdDisplay.Ashas has checked to see how many apps are installed, and specifically if Facebook or FB Messenger are installed.[3] |
S0422 | Anubis |
Anubis can collect a list of installed applications to compare to a list of targeted applications.[4] |
S1079 | BOULDSPY |
BOULDSPY can retrieve the list of installed applications.[5] |
C0033 | C0033 |
During C0033, PROMETHIUM used StrongPity to obtain a list of installed applications.[6] |
S0529 | CarbonSteal |
CarbonSteal has looked for specific applications, such as MiCode.[7] |
S0480 | Cerberus | |
S1083 | Chameleon | |
S0479 | DEFENSOR ID |
DEFENSOR ID can retrieve a list of installed applications.[10] |
S0505 | Desert Scorpion |
Desert Scorpion can obtain a list of installed applications.[11] |
S0550 | DoubleAgent |
DoubleAgent has accessed the list of installed apps.[7] |
S0478 | EventBot | |
S0405 | Exodus | |
S0509 | FakeSpy | |
S0408 | FlexiSpy | |
S0423 | Ginp | |
S0535 | Golden Cup |
Golden Cup can obtain a list of installed applications.[17] |
S0551 | GoldenEagle |
GoldenEagle has collected a list of installed application names.[7] |
S0421 | GolfSpy | |
S0536 | GPlayed | |
S0544 | HenBox | |
S1077 | Hornbill |
Hornbill can search for installed applications such as WhatsApp.[21] |
S0463 | INSOMNIA |
INSOMNIA can obtain a list of installed non-Apple applications.[22] |
S0485 | Mandrake | |
S0407 | Monokle | |
S0399 | Pallas |
Pallas retrieves a list of all applications installed on the device.[25] |
S0316 | Pegasus for Android |
Pegasus for Android accesses the list of installed applications.[26] |
S0539 | Red Alert 2.0 |
Red Alert 2.0 can obtain the running application.[27] |
S0403 | Riltok |
Riltok can retrieve a list of installed applications. Installed application names are then checked against an adversary-defined list of targeted applications.[28] |
S0411 | Rotexy |
Rotexy retrieves a list of installed applications and sends it to the command and control server.[29] |
S1062 | S.O.V.A. |
S.O.V.A. can search for installed applications that match a list of targets.[30] |
S0328 | Stealth Mango |
Stealth Mango uploads information about installed packages.[31] |
S1082 | Sunbird |
Sunbird can exfiltrate a list of installed applications.[21] |
S1069 | TangleBot | |
S0545 | TERRACOTTA |
TERRACOTTA can obtain a list of installed apps.[33] |
S0558 | Tiktok Pro |
Tiktok Pro can obtain a list of installed applications.[34] |
S0424 | Triada |
Triada is able to modify code within the com.android.systemui application to gain access to |
S0427 | TrickMo | |
S0418 | ViceLeaker |
ViceLeaker can obtain a list of installed applications.[37] |
S0489 | WolfRAT | |
S0311 | YiSpecter |
YiSpecter has collected information about installed applications.[39] |
ID | Mitigation | Description |
---|---|---|
M1006 | Use Recent OS Version |
Android 11 introduced privacy enhancements to package visibility, filtering results that are returned from the package manager. iOS 12 removed the private API that could previously be used to list installed applications on non-app store applications.[40] |
M1011 | User Guidance |
iOS users should be instructed to not download applications from unofficial sources, as applications distributed via the Apple App Store cannot list installed applications on a device. |
ID | Data Source | Data Component | Detects |
---|---|---|---|
DS0041 | Application Vetting | API Calls |
Application vetting services could look for the Android permission |