Compliance Node Overview
MITRE ATT&CK T1626.001 (Device Administrator Permissions) is an ATT&CK for Mobile Privilege Escalation sub-technique of T1626 (Abuse Elevation Control Mechanism). Adversaries may abuse Android's device administration API to obtain a higher degree of control over the device. By abusing the API, adversaries can perform several nefarious actions, such as resetting the device's password for Endpoint Denial of Service, factory resetting the device for File Deletion and to delete any traces of the malware, disabling all the device's cameras, or to make it more difficult to uninstall the app. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1626/001/
SHA-256 integrity: 4d90b8fad1169ec6c4a92045ae82e397d851a3ee9a7c12d6328feed34577d684
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1626.001: Device Administrator Permissions (https://attack.mitre.org/techniques/T1626/001/)
- MITRE ATT&CK Mobile Tactic TA0029: Privilege Escalation (https://attack.mitre.org/tactics/TA0029/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.