# T1521 Encrypted Channel

> As of 2026-10-05, T1521 (Encrypted Channel) appears in 12 tracked threats, first reported 2026-05-11 and most recently 2026-09-23; it most often appears alongside T1646 (Exfiltration Over C2 Channel).

- **Tracked threats:** 12 (3 critical, 8 high, 1 medium)
- **First seen:** 2026-05-11
- **Last seen:** 2026-09-23
- **Detection rules:** 25 (counts only; Blue tier and above)

## Key facts

- **ID:** T1521
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1521/

## Activity timeline

T1521 first appeared in tracked threats on 2026-05-11 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 6 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1521 Encrypted Channel is catalogued by MITRE ATT&CK under the Command and Control (Mobile) tactic in the Mobile matrix. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 8 high, 1 medium.

Threats that use T1521 most often also use [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (10 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (8 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (8 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (8 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Tracked threats

12 tracked threats use T1521.

- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption](https://intel.threadlinqs.com/threat/TL-2026-2591) — critical — 2026-09-20
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as…](https://intel.threadlinqs.com/threat/TL-2026-1798) — medium — 2026-07-31
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…](https://intel.threadlinqs.com/threat/TL-2026-1717) — high — 2026-07-27
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11

## Detection coverage

Threadlinqs maintains 25 detection rules mapped to T1521 (SPL 9, KQL 10, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

25 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1521.001 Symmetric Cryptography — 1 tracked threat
- T1521.002 Asymmetric Cryptography — 0 tracked threats
- T1521.003 SSL Pinning — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1521
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
