SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Search Application Repositories

Hackers often browse public app stores like Google Play or the Apple App Store to find apps that use AI. Think of it like a thief walking through a public library to see which books contain specific secrets before deciding which ones to steal.

Adversaries perform reconnaissance by searching public application repositories—such as Google Play, the iOS App Store, or the Microsoft Store—to identify targets that utilize AI-enabled components. This activity is a common precursor to acquiring public AI artifacts for further analysis or exploitation.

Adversaries conduct reconnaissance by querying open application repositories, including but not limited to Google Play, the iOS App Store, the macOS App Store, and the Microsoft Store, to identify software packages containing AI-enabled components. This technique serves as a targeting mechanism to facilitate the subsequent acquisition of public AI artifacts (AML.T0002) for reverse engineering, model extraction, or vulnerability research.


← all terms