# T1481 Web Service

> As of 2026-10-05, T1481 (Web Service) appears in 11 tracked threats, first reported 2026-02-16 and most recently 2026-09-03, with linked actors including APT37, Intellexa Consortium, MoYu Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 11 (11 high)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-03
- **Threat actors:** 4
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1481
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1481/

## Activity timeline

T1481 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-03. The busiest month was 2026-07 with 3 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1481 Web Service is catalogued by MITRE ATT&CK under the Command and Control (Mobile) tactic in the Mobile matrix. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 11 high.

Threats that use T1481 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (10 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (10 threats), [T1429 Audio Capture](https://intel.threadlinqs.com/technique/T1429) (7 threats), [T1430 Location Tracking](https://intel.threadlinqs.com/technique/T1430) (7 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1481; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (1), [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (1), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1
- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 1
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

11 tracked threats use T1481.

- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware Targets](https://intel.threadlinqs.com/threat/TL-2026-2016) — high — 2026-08-14
- [SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…](https://intel.threadlinqs.com/threat/TL-2026-1717) — high — 2026-07-27
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human…](https://intel.threadlinqs.com/threat/TL-2026-0751) — high — 2026-06-10
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil…](https://intel.threadlinqs.com/threat/TL-2026-0407) — high — 2026-04-22
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1481, most frequent first.

- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2023-41061](https://intel.threadlinqs.com/cve/CVE-2023-41061)
- [CVE-2023-41064](https://intel.threadlinqs.com/cve/CVE-2023-41064)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1481 (SPL 6, KQL 6, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1481.001 Dead Drop Resolver — 2 tracked threats
- T1481.002 Bidirectional Communication — 3 tracked threats
- T1481.003 One-Way Communication — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1481
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
