Activity timeline
T1624.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 3 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1624.001 Broadcast Receivers is catalogued by MITRE ATT&CK under the Persistence (Mobile) tactic in the Mobile matrix, as a sub-technique of T1624 Event Triggered Execution. Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 1 medium.
Threats that use T1624.001 most often also use T1660 Phishing (9 threats), T1418 Software Discovery (8 threats), T1636.003 Contact List (8 threats), T1636.004 SMS Messages (7 threats), T1426 System Information Discovery (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1624.001; the most frequent are NSO Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1624.001.
Threat actors using it
Tracked threats
10 tracked threats use T1624.001.
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…high
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europehigh
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Accesshigh
- Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…medium
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and…critical
- SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolutionhigh
Detection coverage
Threadlinqs maintains 23 detection rules mapped to T1624.001 (SPL 10, KQL 5, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1624 Event Triggered Execution — 19 tracked threats at the technique level.