# T1070.006 Timestomp

> As of 2026-10-05, T1070.006 (Timestomp) appears in 37 tracked threats, first reported 2026-02-15 and most recently 2026-10-03, with linked actors including ClickLock Dev, Velvet Ant, APT37; it most often appears alongside T1036.005 (Match Legitimate Resource Name or Location).

- **Tracked threats:** 37 (10 critical, 25 high, 2 medium)
- **First seen:** 2026-02-15
- **Last seen:** 2026-10-03
- **Threat actors:** 17
- **Detection rules:** 47 (counts only; Blue tier and above)

## Key facts

- **ID:** T1070.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Parent:** T1070
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1070/006/

## Activity timeline

T1070.006 first appeared in tracked threats on 2026-02-15 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 10 reports, and 37 of the 37 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1070.006 Timestomp is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix, as a sub-technique of [T1070 Indicator Removal](https://intel.threadlinqs.com/technique/T1070). Threadlinqs maps 37 of 2623 tracked threats (1.4%) to it; by severity that is 10 critical, 25 high, 2 medium.

Threats that use T1070.006 most often also use [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (25 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (25 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (20 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (20 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

17 tracked threat actors appear in the threats that use T1070.006; the most frequent are [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (2), [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) (2), [APT37](https://intel.threadlinqs.com/actor/APT37) (1), [APT38](https://intel.threadlinqs.com/actor/APT38) (1), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (1).

## Data sources

Telemetry that can reveal T1070.006, per MITRE ATT&CK.

- Command — Command Execution
- File — File Metadata, File Modification
- Process — OS API Execution

## Threat actors using it

- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 2
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators) — 1
- [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik) — 1
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 1
- [PolinRider](https://intel.threadlinqs.com/actor/PolinRider) — 1
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945) — 1

## Tracked threats

The 30 most recent of 37 tracked threats that use T1070.006.

- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts](https://intel.threadlinqs.com/threat/TL-2026-2296) — high — 2026-09-02
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web…](https://intel.threadlinqs.com/threat/TL-2026-2096) — high — 2026-08-21
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5…](https://intel.threadlinqs.com/threat/TL-2026-1971) — high — 2026-08-10
- [Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1904) — critical — 2026-08-05
- [Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1871) — high — 2026-08-04
- [CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive…](https://intel.threadlinqs.com/threat/TL-2026-1857) — high — 2026-08-04
- [Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx\[.\]top)](https://intel.threadlinqs.com/threat/TL-2026-1621) — high — 2026-07-22
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest…](https://intel.threadlinqs.com/threat/TL-2026-1444) — high — 2026-07-17
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…](https://intel.threadlinqs.com/threat/TL-2026-1286) — high — 2026-07-13
- [Vidar Infostealer and XMRig Cryptominer Malvertising Campaign Targeting SMBs (Factory-v3 / X3D MINER)](https://intel.threadlinqs.com/threat/TL-2026-1183) — medium — 2026-07-10
- [UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on…](https://intel.threadlinqs.com/threat/TL-2026-1162) — high — 2026-07-10
- [North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in…](https://intel.threadlinqs.com/threat/TL-2026-1111) — high — 2026-07-05
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as…](https://intel.threadlinqs.com/threat/TL-2026-1088) — high — 2026-07-02
- [Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity…](https://intel.threadlinqs.com/threat/TL-2026-0866) — high — 2026-06-19
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistence](https://intel.threadlinqs.com/threat/TL-2026-0807) — critical — 2026-06-15
- [DBatLoader (ModiLoader/NatsoLoader): Delphi-Compiled Windows Loader Using Layered Anti-Analysis…](https://intel.threadlinqs.com/threat/TL-2026-0768) — high — 2026-06-10
- [Lazarus RemotePE Memory-Only RAT — DPAPILoader + RemotePELoader Chain Targeting Financial & Cryptocurrency…](https://intel.threadlinqs.com/threat/TL-2026-0579) — high — 2026-05-25
- [Operation GriefLure — China-Nexus APT Spear-Phishing Targeting Viettel (Vietnam Military Telecom) and St.…](https://intel.threadlinqs.com/threat/TL-2026-0476) — high — 2026-05-07
- [Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…](https://intel.threadlinqs.com/threat/TL-2026-0456) — high — 2026-05-04
- [Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…](https://intel.threadlinqs.com/threat/TL-2026-0424) — high — 2026-04-25

## Related CVEs

CVEs referenced by the tracked threats that use T1070.006, most frequent first.

- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2019-16098](https://intel.threadlinqs.com/cve/CVE-2019-16098)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2021-23758](https://intel.threadlinqs.com/cve/CVE-2021-23758)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-37042](https://intel.threadlinqs.com/cve/CVE-2022-37042)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769)

## Detection coverage

Threadlinqs maintains 47 detection rules mapped to T1070.006 (SPL 14, KQL 12, Sigma 21). Rule content is available to Blue tier accounts and above; this page shows counts only.

47 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1070 Indicator Removal](https://intel.threadlinqs.com/technique/T1070) — 432 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1070.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
