# T1407 Download New Code at Runtime

> As of 2026-10-05, T1407 (Download New Code at Runtime) appears in 20 tracked threats, first reported 2026-03-07 and most recently 2026-09-20, with linked actors including MoYu Group, APT37, NSO Group; it most often appears alongside T1437 (Application Layer Protocol).

- **Tracked threats:** 20 (2 critical, 17 high, 1 medium)
- **First seen:** 2026-03-07
- **Last seen:** 2026-09-20
- **Threat actors:** 3
- **Detection rules:** 33 (counts only; Blue tier and above)

## Key facts

- **ID:** T1407
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1407/

## Activity timeline

T1407 first appeared in tracked threats on 2026-03-07 and was most recently reported on 2026-09-20. The busiest month was 2026-08 with 7 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1407 Download New Code at Runtime is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 2 critical, 17 high, 1 medium.

Threats that use T1407 most often also use [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (16 threats), [T1406 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1406) (12 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (12 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (12 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (11 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1407; the most frequent are [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (2), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1407.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)

## Threat actors using it

- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

20 tracked threats use T1407.

- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — high — 2026-08-25
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe](https://intel.threadlinqs.com/threat/TL-2026-1995) — high — 2026-08-12
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [CVE-2026-20971: Eight-Year-Old Samsung Knox PROCA/FIVE Kernel Use-After-Free in /proc/pid/integrity Handlers](https://intel.threadlinqs.com/threat/TL-2026-0925) — high — 2026-06-24
- [Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum…](https://intel.threadlinqs.com/threat/TL-2026-0858) — high — 2026-06-18
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07

## Related CVEs

CVEs referenced by the tracked threats that use T1407, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2026-20971](https://intel.threadlinqs.com/cve/CVE-2026-20971)

## Detection coverage

Threadlinqs maintains 33 detection rules mapped to T1407 (SPL 11, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

33 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1407
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
