Skip to content

Threat actor

Mobilewalla

Last fetched

Mobilewalla is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Mobilewalla is a data broker and consumer intelligence platform that aggregates and analyzes large amounts of consumer data. It was founded in Singapore and later moved its headquarters to Atlanta, Georgia, U.S. Mobilewalla collected over 500 million unique consumer advertising identifiers paired with precise location data, often without consumer knowledge or consent. This data revealed sensitive information, such as visits to healthcare facilities, religious institutions, and political events. Mobilewalla also tracked residents of domestic abuse shelters and purposefully tracked protesters in 2020. In addition, Mobilewalla admitted that it supplied data used by the U.S Department of Homeland Security, the U.S Internal Revenue Service (IRS), and the U.S. military for warrantless device tracking domestically and internationally. The Federal Trade Commission (FTC) stated that Mobilewalla failed to anonymize this data. In response to these practices, the FTC finalized an order in 2025 banning Mobilewalla from selling sensitive location data and collecting consumer data.

Techniques by tactic

No ATT&CK techniques are recorded for Mobilewalla in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Mobilewalla today — this states the absence of a published link, not that Mobilewalla has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Mobilewalla into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.