Activity timeline
T1624 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 12 reports, and 19 of the 19 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1624 Event Triggered Execution is catalogued by MITRE ATT&CK under the Persistence (Mobile) tactic in the Mobile matrix. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 2 critical, 14 high, 2 medium, 1 low.
Threats that use T1624 most often also use T1417 Input Capture (17 threats), T1437 Application Layer Protocol (17 threats), T1426 System Information Discovery (14 threats), T1646 Exfiltration Over C2 Channel (14 threats), T1660 Phishing (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
Mitigations
MITRE ATT&CK lists 1 mitigation for T1624.
Tracked threats
19 tracked threats use T1624.
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Servicehigh
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…high
- Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emergeshigh
- Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…low
- Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Adsmedium
- SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…high
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…medium
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutionshigh
- Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…high
- Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loaderhigh
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…critical
- Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…high
- Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Playhigh
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…high
- TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…high
- NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil…high
- Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Usershigh
Detection coverage
Threadlinqs maintains 19 detection rules mapped to T1624 (SPL 6, KQL 5, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1624.001 Broadcast Receivers — 10 tracked threats