1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1582 SMS Control — Attack Simulation

Adversaries may delete, alter, or send SMS messages without user authorization. This could be used to hide C2 SMS messages, spread malware, or various external effects. This can be accomplished by requesting the `RECEIVE_SMS` or `SEND_SMS` permissions depending on what the malware is attempting to do. If the app is set as the default SMS handler on the device, the `SMS_DELIVER` broadcast intent can be registered, which allows the app to write to…

Technique description

Adversaries may delete, alter, or send SMS messages without user authorization. This could be used to hide C2 SMS messages, spread malware, or various external effects. This can be accomplished by requesting the `RECEIVE_SMS` or `SEND_SMS` permissions depending on what the malware is attempting to do. If the app is set as the default SMS handler on the device, the `SMS_DELIVER` broadcast intent can be registered, which allows the app to write to…

No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.

Official ATT&CK definition · Detection rules and anomaly models

Documented simulation candidates

No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.

Connected ecosystem references

Linked tags

Detection and collection

T1582 detection workspace

Attack tools

No reviewed association in this snapshot.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.