Activity timeline
T1407 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 7 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1407 Download New Code at Runtime is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 2 critical, 17 high, 1 medium.
Threats that use T1407 most often also use T1437 Application Layer Protocol (16 threats), T1406 Obfuscated Files or Information (12 threats), T1426 System Information Discovery (12 threats), T1660 Phishing (12 threats), T1418 Software Discovery (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1407; the most frequent are MoYu Group (2), APT37 (1), NSO Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1407.
Threat actors using it
Tracked threats
20 tracked threats use T1407.
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokhigh
- First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnethigh
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnethigh
- WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europehigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…high
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committeecritical
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- CVE-2026-20971: Eight-Year-Old Samsung Knox PROCA/FIVE Kernel Use-After-Free in /proc/pid/integrity Handlershigh
- Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum…high
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commandshigh
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…high
- Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…medium
- ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn…high
- Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Usershigh
Detection coverage
Threadlinqs maintains 33 detection rules mapped to T1407 (SPL 11, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.