Activity timeline
T1437 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 34 of the 34 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1437 Application Layer Protocol is catalogued by MITRE ATT&CK under the Command and Control (Mobile) tactic in the Mobile matrix. Threadlinqs maps 34 of 2623 tracked threats (1.3%) to it; by severity that is 3 critical, 29 high, 1 medium, 1 low.
Threats that use T1437 most often also use T1660 Phishing (24 threats), T1406 Obfuscated Files or Information (23 threats), T1417 Input Capture (22 threats), T1646 Exfiltration Over C2 Channel (22 threats), T1426 System Information Discovery (21 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1437; the most frequent are MoYu Group (2), NSO Group (2), APT37 (1), Cyber Av3ngers (1), Interlock (1).
Threat actors using it
Tracked threats
The 30 most recent of 34 tracked threats that use T1437.
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokhigh
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum…high
- First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnethigh
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnethigh
- WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraudhigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…high
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…low
- SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…high
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…medium
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…high
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutionshigh
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…critical
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…high
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum…high
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commandshigh
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…high
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)high
- FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…high
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…high
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…critical
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…high
Detection coverage
Threadlinqs maintains 53 detection rules mapped to T1437 (SPL 18, KQL 18, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1437.001 Web Protocols — 9 tracked threats