{
  "node_id": "mitre-attack-mobile-t1636-003-contact-list",
  "title": "MITRE ATT&CK Mobile T1636.003: Contact List (Mobile Tactic TA0035 - Collection)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1636.003 (Contact List) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather contact list data. On Android, this can be accomplished using the Contacts Content Provider. On iOS, this can be accomplished using the Contacts framework. If the device has been jailbroken or rooted, an adversary may be able to access the Contact List without the user's knowledge or approval. Affected platforms: iOS, Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-mobile-t1636-protected-user-data"
  ],
  "primary_citations_count": 6
}