Skip to content
Skip to main content
Mobile Extractions Technical Explainer

Could the handset have been remotely accessed or controlled?

Possibly, but first distinguish activity through the same account on another client from direct control of the physical handset.

The mechanisms leave different evidence

A linked desktop, compromised token or second phone can create account activity that later synchronises to the handset. Direct control may involve support, administration, accessibility or malware tools with relevant permissions. Enterprise management can issue still other commands.

Require a mechanism at the relevant time

Check installed services, permissions, linked-client lists, authentication changes, session and network records, and local interaction. A cloud address alone does not prove control, while technical possibility alone does not make remote use a realistic explanation. Specialist interpretation may be needed to connect the software, session and event.

Key takeaway

Identify whether the account or handset was controlled remotely and support that explanation with relevant software, session and timing evidence.

Reference: MEX-005Mobile Extractions