What MITRE ATT&CK Mobile T1417: Input Capture (Credential Access + Collection) requires
MITRE ATT&CK Mobile T1417 covers adversary capture of user input via keylogging, accessibility-service abuse, overlay attacks, or screenshot interception. Cerberus, BRATA, ERMAC, and Hook Android bankers abuse accessibility services to read PIN entry. iOS variants leverage AssistiveTouch and screen recording. Compliance: NIST SP 800-124 Rev 2, PCI MPoC for mobile payment, HIPAA 164.312(d), GDPR Article 32.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1417/
SHA-256 integrity: 778000b0e8def1a83fb6597e5ee8a9cb222cb593fa244319fedc898f988ca047
Primary Citations — 6 traced to source
- MITRE ATT&CK Mobile T1417: Input Capture (https://attack.mitre.org/techniques/T1417/)
- NIST SP 800-124 Rev 2
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.