What MITRE ATT&CK Mobile T1628.002: User Evasion (Mobile Tactic TA0030 - Defense Evasion) requires
MITRE ATT&CK T1628.002 (User Evasion) is an ATT&CK for Mobile Defense Evasion sub-technique of T1628 (Hide Artifacts). Adversaries may attempt to avoid detection by hiding malicious behavior from the user. By doing this, an adversary's modifications would most likely remain installed on the device for longer, allowing the adversary to continue to operate on that device. While there are many ways this can be accomplished, one method is by using the device's sensors. By utilizing the various motion sensors on a device, such as accelerometer or gyroscope, an application could detect that the device is being interacted with. Affected platforms: Android. MITRE-documented mitigations include M1010 Deploy Compromised Device Detection Method. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1628/002/
SHA-256 integrity: 82b3ba0432b74cdbb641d96e306d0a13ceded93338e0ba8beaafb0f6d86a1623
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1628.002: User Evasion (https://attack.mitre.org/techniques/T1628/002/)
- MITRE ATT&CK Mobile Tactic TA0030: Defense Evasion (https://attack.mitre.org/tactics/TA0030/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-mobile-t1628-002-user-evasion.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-mobile-t1628-002-user-evasion.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-mobile-t1628-002-user-evasion
- Back to registry: Browse all 10,085 compliance nodes