Activity timeline
T1636.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 6 reports, and 17 of the 17 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1636.003 Contact List is catalogued by MITRE ATT&CK under the Collection (Mobile) tactic in the Mobile matrix, as a sub-technique of T1636 Protected User Data. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 16 high.
Threats that use T1636.003 most often also use T1636.004 SMS Messages (14 threats), T1660 Phishing (13 threats), T1418 Software Discovery (10 threats), T1541 Foreground Persistence (10 threats), T1513 Screen Capture (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1636.003; the most frequent are Cyber Av3ngers (1), NSO Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1636.003.
Threat actors using it
Tracked threats
17 tracked threats use T1636.003.
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritizationhigh
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Memberhigh
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…high
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic…high
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraudhigh
- WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europehigh
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…high
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Accesshigh
- ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…high
- SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolutionhigh
- ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…high
Detection coverage
Threadlinqs maintains 28 detection rules mapped to T1636.003 (SPL 9, KQL 11, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1636 Protected User Data — 27 tracked threats at the technique level.