T1636.003 Contact List
Adversaries may utilize standard operating system APIs to gather contact list data. On Android, this can be accomplished using the Contacts Content Provider. On iOS, this can be accomplished using the Contacts framework.
If the device has been jailbroken or rooted, an adversary may be able to access the Contact List without the user’s knowledge or approval.
| Item | Value |
|---|---|
| ID | T1636.003 |
| Sub-techniques | T1636.001, T1636.002, T1636.003, T1636.004, T1636.005 |
| Tactics | TA0035 |
| Platforms | Android, iOS |
| Version | 1.1 |
| Created | 01 April 2022 |
| Last Modified | 24 October 2025 |
Procedure Examples
| ID | Name | Description |
|---|---|---|
| S1061 | AbstractEmu | AbstractEmu can grant itself contact list access.55 |
| S0309 | Adups | Adups transmitted contact lists.45 |
| S1095 | AhRat | AhRat can collect the device’s contact list.22 |
| S0304 | Android/Chuli.A | Android/Chuli.A stole contact list data stored both on the the phone and the SIM card.49 |
| S0292 | AndroRAT | AndroRAT collects contact list information.4746 |
| S0422 | Anubis | Anubis can steal the device’s contact list.41 |
| S0540 | Asacub | Asacub can collect the device’s contact list.39 |
| S1079 | BOULDSPY | BOULDSPY can exfiltrate a device’s contacts.12 |
| C0033 | C0033 | During C0033, PROMETHIUM used StrongPity to collect the device’s contact list.60 |
| S0480 | Cerberus | Cerberus can obtain the device’s contact list.21 |
| S0323 | Charger | Charger steals contacts from the victim user’s device.52 |
| S0425 | Corona Updates | Corona Updates can collect device contacts.37 |
| S1243 | DCHSpy | DCHSpy has accessed the device’s contact list.13 |
| S0505 | Desert Scorpion | Desert Scorpion can collect the device’s contact list.40 |
| S0550 | DoubleAgent | DoubleAgent has accessed the contact list.2 |
| S0507 | eSurv | eSurv can exfiltrate the device’s contact list.25 |
| S0522 | Exobot | Exobot can access the device’s contact list.50 |
| S0405 | Exodus | Exodus Two can download the address book.26 |
| S1080 | Fakecalls | Fakecalls can copy and exfiltrate a device’s contact list.28 |
| S0509 | FakeSpy | FakeSpy can collect the device’s contact list.56 |
| S0408 | FlexiSpy | FlexiSpy can collect device contacts.1 |
| S1067 | FluBot | FluBot has used the contact list to infect more devices.1516 |
| S0423 | Ginp | Ginp can download the device’s contact list.58 |
| S1231 | GodFather | GodFather has accessed the device’s contact list.29 |
| S0535 | Golden Cup | Golden Cup can collect the device’s contact list.42 |
| S0551 | GoldenEagle | GoldenEagle has collected a list of contacts.2 |
| S0421 | GolfSpy | GolfSpy can obtain the device’s contact list.20 |
| S0536 | GPlayed | GPlayed can access the device’s contact list.18 |
| S0406 | Gustuff | Gustuff can collect the contact list.34 |
| S0544 | HenBox | HenBox can access the device’s contact list.54 |
| S1128 | HilalRAT | HilalRAT can retrieve a device’s contact list.23 |
| S1077 | Hornbill | Hornbill can collect device contacts.5 |
| S0463 | INSOMNIA | INSOMNIA can collect the device’s contact list.38 |
| S1185 | LightSpy | LightSpy has accessed the device’s contact list.8101197 |
| S0485 | Mandrake | Mandrake can access the device’s contact list.4 |
| S0407 | Monokle | Monokle can retrieve the device’s contact list.43 |
| S0399 | Pallas | Pallas accesses the device contact list.36 |
| S0316 | Pegasus for Android | Pegasus for Android accesses contact list information.53 |
| S0289 | Pegasus for iOS | Pegasus for iOS gathers contacts from the system by dumping the victim’s address book.35 |
| S1126 | Phenakite | Phenakite can exfiltrate the victim device’s contact list.51 |
| S1241 | RatMilad | RatMilad has accessed the device’s contact list.3 |
| S0539 | Red Alert 2.0 | Red Alert 2.0 can collect the device’s contact list.24 |
| S0403 | Riltok | Riltok can access and upload the device’s contact list to the command and control server.19 |
| S0411 | Rotexy | Rotexy can access and upload the contacts list to the command and control server.14 |
| S0549 | SilkBean | SilkBean can access device contacts.2 |
| S1195 | SpyC23 | SpyC23 can exfiltrate the victim device’s contact list.333132 |
| S0324 | SpyDealer | SpyDealer harvests contact lists from victims.48 |
| S0305 | SpyNote RAT | SpyNote RAT can view contacts.27 |
| S0328 | Stealth Mango | Stealth Mango uploads contact lists for various third-party applications such as Yahoo, AIM, GoogleTalk, Skype, QQ, and others.44 |
| S1082 | Sunbird | Sunbird can exfiltrate a device’s contacts.5 |
| S1069 | TangleBot | TangleBot can request permission to view device contacts.17 |
| S0558 | Tiktok Pro | Tiktok Pro can access the device’s contact list.57 |
| S0506 | ViperRAT | ViperRAT can collect the device’s contact list.6 |
| G0112 | Windshift | Windshift has included contact list exfiltration in the malicious apps deployed as part of Operation BULL.59 |
| S0489 | WolfRAT | WolfRAT can collect the device’s contact list.30 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1011 | User Guidance | Contact list access is an uncommonly needed permission, so users should be instructed to use extra scrutiny when granting access to their contact list. |
References
-
Actis B. (2017, April 22). FlexSpy Application Analysis. Retrieved September 4, 2019. ↩
-
A. Kumar, K. Del Rosso, J. Albrecht, C. Hebeisen. (2020, June 1). Mobile APT Surveillance Campaigns Targeting Uyghurs - A collection of long-running Android tooling connected to a Chinese mAPT actor. Retrieved November 10, 2020. ↩↩↩
-
Gupta, N. (2022, October 5). We Smell A RatMilad Android Spyware. Retrieved August 27, 2025. ↩
-
R. Gevers, M. Tivadar, R. Bleotu, A. M. Barbatei, et al.. (2020, May 14). Uprooting Mandrake: The Story of an Advanced Android Spyware Framework That Went Undetected for 4 Years. Retrieved July 15, 2020. ↩
-
Apurva Kumar, Kristin Del Rosso. (2021, February 10). Novel Confucius APT Android Spyware Linked to India-Pakistan Conflict. Retrieved June 9, 2023. ↩↩
-
M. Flossman. (2017, February 16). ViperRAT: The mobile APT targeting the Israeli Defense Force that should be on your radar. Retrieved September 11, 2020. ↩
-
Dmitry Bestuzhev. (2025, April 7). The Coordinated Kill Switch: LightSpy’s iOS Destructive Plugin Architecture Manages Device Disablement. Retrieved April 14, 2025. ↩
-
Melikov, D. (2024, April 11). LightSpy Returns: Renewed Espionage Campaign Targets Southern Asia, Possibly India. Retrieved January 14, 2025. ↩
-
Shoshin, P. (2020, March 27). LightSpy spyware targets iPhone users in Hong Kong. Retrieved February 12, 2025. ↩
-
ThreatFabric. (2023, October 2). LightSpy mAPT Mobile Payment System Attack. Retrieved January 17, 2025. ↩
-
ThreatFabric. (2024, October 29). LightSpy: Implant for iOS. Retrieved January 30, 2025. ↩
-
Kyle Schmittle, Alemdar Islamoglu, Paul Shunk, Justin Albrecht. (2023, April 27). Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy. Retrieved July 21, 2023. ↩
-
Albrecht, J., Islamoglu, A. (2025, July 21). Lookout Discovers Iranian APT MuddyWater Leveraging DCHSpy During Israel-Iran Conflict . Retrieved September 19, 2025. ↩
-
T. Shishkova, L. Pikman. (2018, November 22). The Rotexy mobile Trojan – banker and ransomware. Retrieved September 23, 2019. ↩
-
Crista Giering, F. Naves, Andrew Conway, Adam McNeil . (2021, April 27). FluBot Android Malware Spreading Rapidly Through Europe, May Hit U.S. Soon. Retrieved February 28, 2023. ↩
-
Europol. (2022, June 1). Takedown of SMS-based FluBot spyware infecting Android phones. Retrieved April 18, 2024. ↩
-
Felipe Naves, Andrew Conway, W. Stuart Jones, Adam McNeil . (2021, September 23). TangleBot: New Advanced SMS Malware Targets Mobile Users Across U.S. and Canada with COVID-19 Lures. Retrieved February 28, 2023. ↩
-
V. Ventura. (2018, October 11). GPlayed Trojan - .Net playing with Google Market . Retrieved November 24, 2020. ↩
-
Tatyana Shishkova. (2019, June 25). Riltok mobile Trojan: A banker with global reach. Retrieved August 7, 2019. ↩
-
E. Xu, G. Guo. (2019, June 28). Mobile Cyberespionage Campaign ‘Bouncing Golf’ Affects Middle East. Retrieved January 27, 2020. ↩
-
Threat Fabric. (2019, August). Cerberus - A new banking Trojan from the underworld. Retrieved June 26, 2020. ↩
-
Lukas Stefanko. (2023, May 23). Android app breaking bad: From legitimate screen recording to file exfiltration within a year. Retrieved December 18, 2023. ↩
-
Agranovich, D., et al. (2022, April). Adversarial Threat Report. Retrieved April 2, 2024. ↩
-
J. Chandraiah. (2018, July 23). Red Alert 2.0: Android Trojan targets security-seekers. Retrieved December 14, 2020. ↩
-
A. Bauer. (2019, April 8). Lookout discovers phishing sites distributing new iOS and Android surveillanceware. Retrieved September 11, 2020. ↩
-
Security Without Borders. (2019, March 29). Exodus: New Android Spyware Made in Italy. Retrieved November 17, 2024. ↩
-
Shivang Desai. (2017, January 23). SpyNote RAT posing as Netflix app. Retrieved January 26, 2017. ↩
-
Igor Golovin. (2022, April 11). Fakecalls: a talking Trojan. Retrieved July 21, 2023. ↩
-
Merkle Science. (2023, April 25). The Godfather Android Malware: Threat under the lens. Retrieved July 16, 2025. ↩
-
W. Mercer, P. Rascagneres, V. Ventura. (2020, May 19). The wolf is back… . Retrieved July 20, 2020. ↩
-
Kohli, P. (2021, November 23). Android APT spyware, targeting Middle East victims, enhances evasiveness. Retrieved November 17, 2024. ↩
-
O’Donnell, L. (2020, September 30). Android Spyware Variant Snoops on WhatsApp, Telegram Messages. Retrieved January 10, 2025. ↩
-
Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024. ↩
-
Vitor Ventura. (2019, April 9). Gustuff banking botnet targets Australia . Retrieved September 3, 2019. ↩
-
Lookout. (2016). Technical Analysis of Pegasus Spyware. Retrieved December 12, 2016. ↩
-
Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018. ↩
-
I. Beer. (2019, August 29). Implant Teardown. Retrieved June 2, 2020. ↩
-
T. Shishkova. (2018, August 28). The rise of mobile banker Asacub. Retrieved December 14, 2020. ↩
-
A. Blaich, M. Flossman. (2018, April 16). Lookout finds new surveillanceware in Google Play with ties to known threat actor targeting the Middle East. Retrieved September 11, 2020. ↩
-
M. Feller. (2020, February 5). Infostealer, Keylogger, and Ransomware in One: Anubis Targets More than 250 Android Applications. Retrieved September 25, 2024. ↩
-
R. Iarchy, E. Rynkowski. (2018, July 5). GoldenCup: New Cyber Threat Targeting World Cup Fans. Retrieved October 29, 2020. ↩
-
Bauer A., Kumar A., Hebeisen C., et al. (2019, July). Monokle: The Mobile Surveillance Tooling of the Special Technology Center. Retrieved September 4, 2019. ↩
-
Lookout. (n.d.). Stealth Mango & Tangelo. Retrieved September 27, 2018. ↩
-
Matt Apuzzo and Michael S. Schmidt. (2016, November 15). Secret Back Door in Some U.S. Phones Sent Data to China, Analysts Say. Retrieved February 6, 2017. ↩
-
Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved March 1, 2024. ↩
-
Lookout. (2016, May 25). 5 active mobile threats spoofing enterprise apps. Retrieved December 19, 2016. ↩
-
Wenjun Hu, Cong Zheng and Zhi Xu. (2017, July 6). SpyDealer: Android Trojan Spying on More Than 40 Apps. Retrieved September 18, 2018. ↩
-
Costin Raiu, Denis Maslennikov, Kurt Baumgartner. (2013, March 26). Android Trojan Found in Targeted Attack. Retrieved December 23, 2016. ↩
-
Threat Fabric. (2017, February). Exobot - Android banking Trojan on the rise. Retrieved October 29, 2020. ↩
-
Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024. ↩
-
Oren Koriat and Andrey Polkovnichenko. (2017, January 24). Charger Malware Calls and Raises the Risk on Google Play. Retrieved January 24, 2017. ↩
-
Mike Murray. (2017, April 3). Pegasus for Android: the other side of the story emerges. Retrieved April 16, 2017. ↩
-
A. Hinchliffe, M. Harbison, J. Miller-Osborn, et al. (2018, March 13). HenBox: The Chickens Come Home to Roost. Retrieved September 9, 2019. ↩
-
P Shunk, K Balaam. (2021, October 28). Rooting Malware Makes a Comeback: Lookout Discovers Global Campaign. Retrieved February 6, 2023. ↩
-
O. Almkias. (2020, July 1). FakeSpy Masquerades as Postal Service Apps Around the World. Retrieved September 15, 2020. ↩
-
S. Desai. (2020, September 8). TikTok Spyware. Retrieved January 5, 2021. ↩
-
ThreatFabric. (2019, November). Ginp - A malware patchwork borrowing from Anubis. Retrieved April 8, 2020. ↩
-
The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021. ↩
-
Stefanko, L. (2023, January 10). StrongPity espionage campaign targeting Android users. Retrieved January 31, 2023. ↩