Compliance Node Overview
MITRE ATT&CK Mobile T1453 (Abuse Accessibility Features) is an Mobile Collection, Credential Access technique. Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices. Accessibility features in Android are designed to assist users with disabilities, performing a variety of tasks, such as using Action Blocks to control lightbulbs, and changing the device’s user interface, such as changing the font size and adjusting contract or colors. One example of how adversaries abuse accessibility features is overlaying an HTML object mimicking a legitimate login screen. The user types their credentials in the overlay HTML object, which is then sent to the adversaries. Another example is a malicious accessibility feature acting as a keylogger. The keylogger monitors changes on the EditText fields and sends it to the adversaries. This method ... Affected platforms: Android. ATT&CK-mapped mitigations: M1011 User Guidance.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1453/
SHA-256 integrity: f425a491171957a772343e6cd8fbf4c3a5af0eeb89b70026750d063211a45f5f
Primary Citations — 7 traced to source
- MITRE ATT&CK Mobile Technique T1453: Abuse Accessibility Features (https://attack.mitre.org/techniques/T1453/)
- MITRE ATT&CK Mobile Tactic TA0035: Collection (https://attack.mitre.org/tactics/TA0035/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.