Activity timeline
T1636.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 6 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1636.004 SMS Messages is catalogued by MITRE ATT&CK under the Collection (Mobile) tactic in the Mobile matrix, as a sub-technique of T1636 Protected User Data. Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 2 critical, 16 high, 1 low.
Threats that use T1636.004 most often also use T1660 Phishing (16 threats), T1636.003 Contact List (14 threats), T1513 Screen Capture (13 threats), T1418 Software Discovery (12 threats), T1541 Foreground Persistence (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
3 tracked threat actors appear in the threats that use T1636.004; the most frequent are Balonx (1), Cyber Av3ngers (1), NSO Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1636.004.
Threat actors using it
Tracked threats
20 tracked threats use T1636.004.
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritizationhigh
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…high
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…high
- Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integrationhigh
- Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Memberhigh
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…high
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…critical
- ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countrieshigh
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlighthigh
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payloadcritical
- Copybara Android RAT Delivered via Fake N26 Support Vishing Callshigh
- Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…low
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…high
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platformhigh
- Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…high
- RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Accesshigh
- ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…high
- SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolutionhigh
- ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…high
Detection coverage
Threadlinqs maintains 36 detection rules mapped to T1636.004 (SPL 10, KQL 16, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1636 Protected User Data — 27 tracked threats at the technique level.