Activity timeline
T1533 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 10 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1533 Data from Local System is catalogued by MITRE ATT&CK under the Collection (Mobile) tactic in the Mobile matrix. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 4 critical, 21 high, 1 low.
Threats that use T1533 most often also use T1437 Application Layer Protocol (20 threats), T1426 System Information Discovery (17 threats), T1646 Exfiltration Over C2 Channel (17 threats), T1660 Phishing (17 threats), T1513 Screen Capture (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
4 tracked threat actors appear in the threats that use T1533; the most frequent are APT37 (1), Balonx (1), GreyVibe (1), MoYu Group (1).
Threat actors using it
Tracked threats
26 tracked threats use T1533.
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnethigh
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraudhigh
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…high
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…low
- SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…high
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutionshigh
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committeecritical
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…critical
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…high
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…high
- GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs &…high
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…critical
- ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame[.]com[.]cn…high
- Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Usershigh
- ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…high
- SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolutionhigh
Detection coverage
Threadlinqs maintains 31 detection rules mapped to T1533 (SPL 9, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.