Adversaries may modify system software binaries to establish persistent access to devices. System software binaries are used by the underlying operating system and users over adb or terminal emulators. Adversaries may make modifications to client software binaries to carry out malicious tasks when those binaries are executed. For example, malware may come with a pre-compiled malicious binary intended to overwrite the genuine one on the device. Since these binaries may be routinely executed by the system or user, the adversary can leverage this for persistent access to the device.
On devices that provide the capability to unlock the bootloader (hence allowing any operating system code to be flashed onto the device), perform periodic checks to ensure that the bootloader is locked.
M1004System Partition IntegrityEnsure that Android devices being used include and enable the Verified Boot capability, which cryptographically ensures the integrity of the system partition.
M1001Security UpdatesInstall security updates in response to discovered vulnerabilities. Purchase devices with a vendor and/or mobile carrier commitment to provide security updates in a prompt manner for a set period of time. Decommission devices that will no longer receive security updates. Limit or block access to enterprise resources from devices that have not installed recent security updates. On Android devices, access can be controlled based on each device's security patch level. On iOS devices, access can be controlled based on the iOS version.
M1002AttestationEnable remote attestation capabilities when available (such as Android SafetyNet or Samsung Knox TIMA Attestation) and prohibit devices that fail the attestation from accessing enterprise resources.
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.