# T1655 Masquerading

> As of 2026-10-05, T1655 (Masquerading) appears in 23 tracked threats, first reported 2026-02-23 and most recently 2026-09-28, with linked actors including MoYu Group; it most often appears alongside T1660 (Phishing).

- **Tracked threats:** 23 (22 high, 1 medium)
- **First seen:** 2026-02-23
- **Last seen:** 2026-09-28
- **Threat actors:** 1
- **Detection rules:** 38 (counts only; Blue tier and above)

## Key facts

- **ID:** T1655
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Evasion (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1655/

## Activity timeline

T1655 first appeared in tracked threats on 2026-02-23 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 7 reports, and 23 of the 23 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1655 Masquerading is catalogued by MITRE ATT&CK under the Defense Evasion (Mobile) tactic in the Mobile matrix. Threadlinqs maps 23 of 2623 tracked threats (0.9%) to it; by severity that is 22 high, 1 medium.

Threats that use T1655 most often also use [T1660 Phishing](https://intel.threadlinqs.com/technique/T1660) (16 threats), [T1513 Screen Capture](https://intel.threadlinqs.com/technique/T1513) (15 threats), [T1437 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1437) (14 threats), [T1646 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1646) (14 threats), [T1417 Input Capture](https://intel.threadlinqs.com/technique/T1417) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1655; the most frequent are [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1655.

- [M1011 User Guidance](https://attack.mitre.org/mitigations/M1011/)

## Threat actors using it

- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 1

## Tracked threats

23 tracked threats use T1655.

- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — high — 2026-09-28
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — high — 2026-09-23
- [Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)](https://intel.threadlinqs.com/threat/TL-2026-2444) — high — 2026-09-11
- [StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok](https://intel.threadlinqs.com/threat/TL-2026-2312) — high — 2026-09-03
- [First Malware Built Specifically for Car Head Units (DoFun TWCore Update-Chain Abuse) Fuels BadBox Botnet](https://intel.threadlinqs.com/threat/TL-2026-2137) — high — 2026-08-25
- [WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud](https://intel.threadlinqs.com/threat/TL-2026-2003) — high — 2026-08-13
- [Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service](https://intel.threadlinqs.com/threat/TL-2026-1841) — high — 2026-08-03
- [Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal…](https://intel.threadlinqs.com/threat/TL-2026-1832) — high — 2026-08-03
- [Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges](https://intel.threadlinqs.com/threat/TL-2026-1757) — high — 2026-07-29
- [Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads](https://intel.threadlinqs.com/threat/TL-2026-1724) — medium — 2026-07-27
- [Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes…](https://intel.threadlinqs.com/threat/TL-2026-1313) — high — 2026-07-14
- [RedHook Android RAT Abuses Wireless ADB via Accessibility Service to Gain Shell-Level Device Access](https://intel.threadlinqs.com/threat/TL-2026-1248) — high — 2026-07-12
- [Rokarolla Android Banking Trojan Intercepts SMS OTPs and Enables Full Device Takeover Across 217+ Banking…](https://intel.threadlinqs.com/threat/TL-2026-1225) — high — 2026-07-11
- [Glitch SPY Android RAT Distributed via Fake Polish Rental App ("Tutaj Dom") Using Brokewell Loader](https://intel.threadlinqs.com/threat/TL-2026-1195) — high — 2026-07-10
- [Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play](https://intel.threadlinqs.com/threat/TL-2026-1059) — high — 2026-07-02
- [Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum…](https://intel.threadlinqs.com/threat/TL-2026-0858) — high — 2026-06-18
- [Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands](https://intel.threadlinqs.com/threat/TL-2026-0826) — high — 2026-06-16
- [BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services…](https://intel.threadlinqs.com/threat/TL-2026-0600) — high — 2026-05-27
- [NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil…](https://intel.threadlinqs.com/threat/TL-2026-0407) — high — 2026-04-22
- [NGate Android Malware — HandyPay-Trojanized NFC Relay Variant Targets Brazilian Cardholders via Fake Rio de…](https://intel.threadlinqs.com/threat/TL-2026-0401) — high — 2026-04-21
- [Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users](https://intel.threadlinqs.com/threat/TL-2026-0192) — high — 2026-03-07
- [ResidentBat — Belarusian KGB Android Spyware at Internet Scale (ADB Sideloading, Custom HTTPS C2, Journalist…](https://intel.threadlinqs.com/threat/TL-2026-0143) — high — 2026-02-25
- [PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote…](https://intel.threadlinqs.com/threat/TL-2026-0135) — high — 2026-02-23

## Detection coverage

Threadlinqs maintains 38 detection rules mapped to T1655 (SPL 17, KQL 11, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

38 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1655.001 Match Legitimate Name or Location — 8 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1655
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
