Skip to content
Every technique
T1663Not expressible in SigmaMOBILE

Remote Access Software

Command and ControlAndroid, iOS

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for mobile platforms. MITRE's telemetry here is mobile EDR and device APIs, which no Sigma rule can address.

What the technique is

Adversaries may use legitimate remote access software, such as VNC, TeamViewer, AirDroid, AirMirror, etc., to establish an interactive command and control channel to target mobile devices. Remote access applications may be installed and used post-compromise as an alternate communication channel for redundant access or as a way to establish an interactive remote session with the target device. They may also be used as a component of malware to establish a reverse connection to an adversary-controlled system or service. Installation of remote access tools may also include persistence.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1689

    Remote access software typically requires many privileged permissions, such as accessibility services or device administrator.

  • AN1690

    Remote access software typically requires many privileged permissions, such as accessibility services or device administrator.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.