Skip to content

Hide Navigation Hide TOC

Uninstall Malicious Application - T1576 (8c7862ff-3449-4ac6-b0fd-ac1298a822a5)

Adversaries may include functionality in malware that uninstalls the malicious application from the device. This can be achieved by:

  • Abusing device owner permissions to perform silent uninstallation using device owner API calls.
  • Abusing root permissions to delete files from the filesystem.
  • Abusing the accessibility service. This requires an intent be sent to the system to request uninstallation, and then abusing the accessibility service to click the proper places on the screen to confirm uninstallation.
Cluster A Galaxy A Cluster B Galaxy B Level
Uninstall Malicious Application - T1576 (8c7862ff-3449-4ac6-b0fd-ac1298a822a5) Attack Pattern Uninstall Malicious Application - T1630.001 (0cdd66ad-26ac-4338-a764-4972a1e17ee3) Attack Pattern 1
Indicator Removal on Host - T1630 (0d4e3bbb-7af5-4c88-a215-0c0906bc1e8d) Attack Pattern Uninstall Malicious Application - T1630.001 (0cdd66ad-26ac-4338-a764-4972a1e17ee3) Attack Pattern 2