Activity timeline
T1070 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 171 reports, and 431 of the 432 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1070 Indicator Removal is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 432 of 2623 tracked threats (16.5%) to it; by severity that is 191 critical, 209 high, 27 medium, 2 low.
Threats that use T1070 most often also use T1059 Command and Scripting Interpreter (329 threats), T1071 Application Layer Protocol (291 threats), T1082 System Information Discovery (269 threats), T1005 Data from Local System (259 threats), T1027 Obfuscated Files or Information (257 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
133 tracked threat actors appear in the threats that use T1070; the most frequent are TeamPCP (16), APT38 (13), Sapphire Sleet (12), Stardust Chollima (12), Contagious Interview (8).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1070.
Data sources
Telemetry that can reveal T1070, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Deletion, File Metadata, File Modification
- Firewall — Firewall Rule Modification
- Network Traffic — Network Traffic Content
- Process — OS API Execution, Process Creation
- Scheduled Job — Scheduled Job Modification
- User Account — User Account Authentication, User Account Deletion
- Windows Registry — Windows Registry Key Deletion, Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 432 tracked threats that use T1070.
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…high
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…critical
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theftcritical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVDhigh
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…critical
- PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…high
- Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…critical
- CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memorycritical
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…critical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Forcehigh
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojancritical
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Processhigh
- Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…high
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
Detection coverage
Threadlinqs maintains 150 detection rules mapped to T1070 (SPL 39, KQL 48, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1070.001 Clear Windows Event Logs — 4 tracked threats
- T1070.002 Clear Linux or Mac System Logs — 6 tracked threats
- T1070.003 Clear Command History — 21 tracked threats
- T1070.004 File Deletion — 207 tracked threats
- T1070.005 Network Share Connection Removal — 1 tracked threat
- T1070.006 Timestomp — 37 tracked threats
- T1070.007 Clear Network Connection History and Configurations — 2 tracked threats
- T1070.008 Clear Mailbox Data — 4 tracked threats
- T1070.009 Clear Persistence — 6 tracked threats
- T1070.010 Relocate Malware — 0 tracked threats