216.73.216.36

T1661: Application Versioning

View on MITRE ATT&CK The MITRE Corporation · Published 22/09/2023 00:16 · Modified 27/03/2026 01:41

Essential information

MITRE technique ID
T1661
Confidence
100/100
Revoked
No
Published
22/09/2023 00:16
Modified
27/03/2026 01:41
Author / Source
The MITRE Corporation

Platforms

android iOS

Description

An adversary may push an update to a previously benign application to add malicious code. This can be accomplished by pushing an initially benign, functional application to a trusted application store, such as the Google Play Store or the Apple App Store. This allows the adversary to establish a trusted userbase that may grant permissions to the application prior to the introduction of malicious code. Then, an application update could be pushed to introduce malicious code.(Citation: android_app_breaking_bad) This technique could also be accomplished by compromising a developer’s account. This would allow an adversary to take advantage of an existing userbase without having to establish the userbase themselves.

Kill chain phases

Kill chainPhase
mitre-mobile-attack defense-evasion
mitre-mobile-attack initial-access

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references