ID | Name |
---|---|
T1629.001 | Prevent Application Removal |
T1629.002 | Device Lockout |
T1629.003 | Disable or Modify Tools |
Adversaries may disable security tools to avoid potential detection of their tools and activities. This can take the form of disabling security software, modifying SELinux configuration, or other methods to interfere with security tools scanning or reporting information. This is typically done by abusing device administrator permissions or using system exploits to gain root access to the device to modify protected system files.
ID | Name | Description |
---|---|---|
S1061 | AbstractEmu |
AbstractEmu can disable Play Protect.[1] |
S0422 | Anubis |
Anubis can modify administrator settings and disable Play Protect.[2] |
S1094 | BRATA |
BRATA can remove installed antivirus applications as well as disable Google Play Protect.[3][4] |
C0033 | C0033 |
During C0033, PROMETHIUM used StrongPity to modify permissions on a rooted device and tried to disable the SecurityLogAgent application.[5] |
S0480 | Cerberus |
Cerberus disables Google Play Protect to prevent its discovery and deletion in the future.[6] |
S1083 | Chameleon | |
S1054 | Drinik |
Drinik can use Accessibility Services to disable Google Play Protect.[8] |
S0420 | Dvmap |
Dvmap can turn off |
S1067 | FluBot |
FluBot can disable Google Play Protect to prevent detection.[10] |
S0485 | Mandrake | |
S0494 | Zen |
ID | Mitigation | Description |
---|---|---|
M1010 | Deploy Compromised Device Detection Method |
Mobile security software can typically detect if a device has been rooted or jailbroken and can inform the user, who can then take appropriate action. |
M1001 | Security Updates |
Security updates frequently contain patches to vulnerabilities that can be exploited for root access. |
M1004 | System Partition Integrity |
System partition integrity mechanisms, such as Verified Boot, can detect the unauthorized modification of system files. |
M1011 | User Guidance |
Users should be taught the dangers of rooting or jailbreaking their device. |
ID | Data Source | Data Component | Detects |
---|---|---|---|
DS0042 | User Interface | System Settings |
The user can view a list of active device administrators in the device settings. |