Obtain Device Cloud Backups (T1470)

View on ATT&CK

In Playbook

Technique & Subtechniques

  • Obtain Device Cloud Backups

Associated Tactics

  • Remote Service Effects

Remote Service Effects (TA0039)

The adversary is trying to control or monitor the device using remote services. This category refers to techniques involving remote services, such as vendor-provided cloud services (e.g. Google Drive, Google Find My Device, or Apple iCloud), or enterprise mobility management (EMM)/mobile device management (MDM) services that an adversary may be able to use to fulfill his or her objectives without access to the mobile device itself.

View on ATT&CK

Procedure Examples

Description Source(s)
Elcomsoft. (n.d.). Elcomsoft Phone Breaker. Retrieved December 29, 2016. Elcomsoft-EPPB
Oleg Afonin. (2017, July 20). Extract and Decrypt WhatsApp Backups from iCloud. Retrieved July 6, 2018. Elcomsoft-WhatsApp
NIST Mobile Threat Catalogue
NIST Mobile Threat Catalogue