# T1533 Data from Local System

> As of 2026-10-05, T1533 (Data from Local System) appears in 26 tracked threats, first reported 2026-02-24 and most recently 2026-09-20, with linked actors including APT37, Balonx, GreyVibe; it most often appears alongside T1437 (Application Layer Protocol).

- **Tracked threats:** 26 (4 critical, 21 high, 1 low)
- **First seen:** 2026-02-24
- **Last seen:** 2026-09-20
- **Threat actors:** 4
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1533
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1533/

## Activity timeline

T1533 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-09-20. The busiest month was 2026-07 with 10 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1533 Data from Local System is catalogued by MITRE ATT&CK under the Collection (Mobile) tactic in the Mobile matrix. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 4 critical, 21 high, 1 low.

Threats that use T1533 most often also use [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (20 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (17 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (17 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (17 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

4 tracked threat actors appear in the threats that use T1533; the most frequent are [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [Balonx](https://intel.threadlinqs.com/actor/Balonx) (1), [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe) (1), [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (1).

## Threat actors using it

- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 1
- [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe) — 1
- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 1

## Tracked threats

26 tracked threats use T1533.

- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — high — 2026-08-25
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…](https://intel.threadlinqs.com/threat/TL-2026-2126) — high — 2026-08-23
- [WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud](https://intel.threadlinqs.com/threat/TL-2026-2003) — high — 2026-08-13
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…](https://intel.threadlinqs.com/threat/TL-2026-1753) — low — 2026-07-29
- [SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…](https://intel.threadlinqs.com/threat/TL-2026-1717) — high — 2026-07-27
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Pegasus Spyware Used Against Former MEP Stelios Kouloglou While Serving on PEGA Committee](https://intel.threadlinqs.com/threat/TL-2026-1110) — critical — 2026-07-05
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [FlagLeft — Microsoft 365 Android Apps Silent Account Takeover via Leftover setIsDebugMode(true) FOCI Token…](https://intel.threadlinqs.com/threat/TL-2026-0671) — high — 2026-06-03
- [GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs &…](https://intel.threadlinqs.com/threat/TL-2026-0622) — high — 2026-05-28
- [OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…](https://intel.threadlinqs.com/threat/TL-2026-0598) — critical — 2026-05-27
- [ScarCruft (APT37) BirdCall Android Variant — Multiplatform Supply-Chain Attack via sqgame\[.\]com\[.\]cn…](https://intel.threadlinqs.com/threat/TL-2026-0460) — high — 2026-05-05
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07
- [ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…](https://intel.threadlinqs.com/threat/TL-2026-0143) — high — 2026-02-25
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1533 (SPL 9, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1533
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
