# T1643 Generate Traffic from Victim

> As of 2026-10-10, T1643 (Generate Traffic from Victim) appears in 10 tracked threats, first reported 2026-02-24 and most recently 2026-10-09, with linked actors including MoYu Group; it most often appears alongside T1426 (System Information Discovery).

- **Tracked threats:** 10 (7 high, 3 medium)
- **First seen:** 2026-02-24
- **Last seen:** 2026-10-09
- **Threat actors:** 1
- **Detection rules:** 9 (counts only; Blue tier and above)

## Key facts

- **ID:** T1643
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-10
- **MITRE:** https://attack.mitre.org/techniques/T1643/

## Activity timeline

T1643 first appeared in tracked threats on 2026-02-24 and was most recently reported on 2026-10-09. The busiest month was 2026-07 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1643 Generate Traffic from Victim is catalogued by MITRE ATT&CK under the Impact (Mobile) tactic in the Mobile matrix. Threadlinqs maps 10 of 2756 tracked threats (0.4%) to it; by severity that is 7 high, 3 medium.

Threats that use T1643 most often also use [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (8 threats), [T1406 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1406) (6 threats), [T1407 Download New Code at Runtime](https://intel.threadlinqs.com/technique/T1407) (6 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (6 threats), [T1418 Software Discovery](https://intel.threadlinqs.com/technique/T1418) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1643; the most frequent are [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1643.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 2

## Tracked threats

10 tracked threats use T1643.

- [Midnight Mimosa: Low-cost MediaTek Android phones ship with firmware-level ad-fraud and residential proxy…](https://intel.threadlinqs.com/threat/TL-2026-3066) — high — 2026-10-09
- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — high — 2026-08-25
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads](https://intel.threadlinqs.com/threat/TL-2026-1724) — medium — 2026-07-27
- [Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise…](https://intel.threadlinqs.com/threat/TL-2026-1667) — medium — 2026-07-24
- ["BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform](https://intel.threadlinqs.com/threat/TL-2026-1636) — high — 2026-07-22
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled…](https://intel.threadlinqs.com/threat/TL-2026-0737) — medium — 2026-06-09
- [NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil…](https://intel.threadlinqs.com/threat/TL-2026-0407) — high — 2026-04-22
- [SURXRAT Android RAT — LLM Module Downloads from Hugging Face, MaaS via Telegram, ArsinkRAT Evolution](https://intel.threadlinqs.com/threat/TL-2026-0142) — high — 2026-02-24

## Detection coverage

Threadlinqs maintains 9 detection rules mapped to T1643 (SPL 2, KQL 4, Sigma 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

9 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1643
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
