# T1636.004 SMS Messages

> As of 2026-10-05, T1636.004 (SMS Messages) appears in 20 tracked threats, first reported 2026-02-16 and most recently 2026-09-28, with linked actors including Balonx, Cyber Av3ngers, NSO Group; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 20 (2 critical, 16 high, 1 low)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-28
- **Threat actors:** 3
- **Detection rules:** 36 (counts only; Blue tier and above)

## Key facts

- **ID:** T1636.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection (Mobile)
- **Matrix:** Mobile
- **Parent:** T1636
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1636/004/

## Activity timeline

T1636.004 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 6 reports, and 20 of the 20 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1636.004 SMS Messages is catalogued by MITRE ATT&CK under the Collection (Mobile) tactic in the Mobile matrix, as a sub-technique of [T1636 Protected User Data](https://intel.threadlinqs.com/technique/T1636). Threadlinqs maps 20 of 2623 tracked threats (0.8%) to it; by severity that is 2 critical, 16 high, 1 low.

Threats that use T1636.004 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (16 threats), [T1636.003 Contact List](https://intel.threadlinqs.com/technique/T1636.003) (14 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (13 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (12 threats), [T1541 Foreground Persistence](https://intel.threadlinqs.com/technique/T1541) (12 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

3 tracked threat actors appear in the threats that use T1636.004; the most frequent are [Balonx](https://intel.threadlinqs.com/actor/Balonx) (1), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (1), [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1636.004.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [Balonx](https://intel.threadlinqs.com/actor/Balonx) — 1
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1
- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

20 tracked threats use T1636.004.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs…](https://intel.threadlinqs.com/threat/TL-2026-2592) — high — 2026-09-20
- [Mantax Otax: Indonesian Android Malware Combines Ransomware with Spyware Integration](https://intel.threadlinqs.com/threat/TL-2026-2719) — high — 2026-09-09
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — high — 2026-09-04
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing…](https://intel.threadlinqs.com/threat/TL-2026-2143) — critical — 2026-08-25
- [ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries](https://intel.threadlinqs.com/threat/TL-2026-2128) — high — 2026-08-24
- [Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight](https://intel.threadlinqs.com/threat/TL-2026-2118) — high — 2026-08-22
- [Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload](https://intel.threadlinqs.com/threat/TL-2026-1881) — critical — 2026-08-05
- [Copybara Android RAT Delivered via Fake N26 Support Vishing Calls](https://intel.threadlinqs.com/threat/TL-2026-1804) — high — 2026-08-01
- [Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan…](https://intel.threadlinqs.com/threat/TL-2026-1753) — low — 2026-07-29
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT…](https://intel.threadlinqs.com/threat/TL-2026-1659) — high — 2026-07-23
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…](https://intel.threadlinqs.com/threat/TL-2026-1313) — high — 2026-07-14
- [RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Access](https://intel.threadlinqs.com/threat/TL-2026-1248) — high — 2026-07-12
- [ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…](https://intel.threadlinqs.com/threat/TL-2026-0143) — high — 2026-02-25
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24
- [ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live…](https://intel.threadlinqs.com/threat/TL-2026-0116) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1636.004, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)

## Detection coverage

Threadlinqs maintains 36 detection rules mapped to T1636.004 (SPL 10, KQL 16, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

36 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1636 Protected User Data](https://intel.threadlinqs.com/technique/T1636) — 27 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1636.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
