# T1624 Event Triggered Execution

> As of 2026-10-05, T1624 (Event Triggered Execution) appears in 19 tracked threats, first reported 2026-03-07 and most recently 2026-08-05; it most often appears alongside T1417 (Input Capture).

- **Tracked threats:** 19 (2 critical, 14 high, 2 medium, 1 low)
- **First seen:** 2026-03-07
- **Last seen:** 2026-08-05
- **Detection rules:** 19 (counts only; Blue tier and above)

## Key facts

- **ID:** T1624
- **Framework:** MITRE ATT&CK
- **Tactics:** Persistence (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1624/

## Activity timeline

T1624 first appeared in tracked threats on 2026-03-07 and was most recently reported on 2026-08-05. The busiest month was 2026-07 with 12 reports, and 19 of the 19 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1624 Event Triggered Execution is catalogued by MITRE ATT&CK under the Persistence (Mobile) tactic in the Mobile matrix. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 2 critical, 14 high, 2 medium, 1 low.

Threats that use T1624 most often also use [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (17 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (17 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (14 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (14 threats), [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (14 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1624.

- [M1006 Use Recent OS Version](https://attack.mitre.org/mitigations/M1006/)

## Tracked threats

19 tracked threats use T1624.

- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…](https://intel.threadlinqs.com/threat/TL-2026-1753) — low — 2026-07-29
- [Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads](https://intel.threadlinqs.com/threat/TL-2026-1724) — medium — 2026-07-27
- [SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App…](https://intel.threadlinqs.com/threat/TL-2026-1717) — high — 2026-07-27
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions](https://intel.threadlinqs.com/threat/TL-2026-1478) — high — 2026-07-18
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [TrickMo.C Android Banking Trojan Adopts TON Blockchain ADNL for Covert C2 Targeting Banking and Crypto Users…](https://intel.threadlinqs.com/threat/TL-2026-0494) — high — 2026-05-11
- [NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil…](https://intel.threadlinqs.com/threat/TL-2026-0407) — high — 2026-04-22
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07

## Detection coverage

Threadlinqs maintains 19 detection rules mapped to T1624 (SPL 6, KQL 5, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

19 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1624.001 Broadcast Receivers](https://intel.threadlinqs.com/technique/T1624.001) — 10 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1624
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
