# T1070 Indicator Removal

> As of 2026-10-05, T1070 (Indicator Removal) appears in 432 tracked threats, first reported 2021-11-25 and most recently 2026-09-27, with linked actors including TeamPCP, APT38, Sapphire Sleet; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 432 (191 critical, 209 high, 27 medium, 2 low)
- **First seen:** 2021-11-25
- **Last seen:** 2026-09-27
- **Threat actors:** 133
- **Detection rules:** 150 (counts only; Blue tier and above)

## Key facts

- **ID:** T1070
- **Framework:** MITRE ATT&CK
- **Tactics:** Stealth (formerly Defense Evasion)
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1070/

## Activity timeline

T1070 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 171 reports, and 431 of the 432 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1070 Indicator Removal is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 432 of 2623 tracked threats (16.5%) to it; by severity that is 191 critical, 209 high, 27 medium, 2 low.

Threats that use T1070 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (329 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (291 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (269 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (259 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (257 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

133 tracked threat actors appear in the threats that use T1070; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (16), [APT38](https://intel.threadlinqs.com/actor/APT38) (13), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (12), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (12), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (8).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1070.

- [M1022 Restrict File and Directory Permissions](https://attack.mitre.org/mitigations/M1022/)
- [M1029 Remote Data Storage](https://attack.mitre.org/mitigations/M1029/)
- [M1041 Encrypt Sensitive Information](https://attack.mitre.org/mitigations/M1041/)

## Data sources

Telemetry that can reveal T1070, per MITRE ATT&CK.

- Application Log — Application Log Content
- Command — Command Execution
- File — File Deletion, File Metadata, File Modification
- Firewall — Firewall Rule Modification
- Network Traffic — Network Traffic Content
- Process — OS API Execution, Process Creation
- Scheduled Job — Scheduled Job Modification
- User Account — User Account Authentication, User Account Deletion
- Windows Registry — Windows Registry Key Deletion, Windows Registry Key Modification

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 16
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 13
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 12
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 12
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 8
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 8
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 7
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 6
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 6
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 5

## Tracked threats

The 30 most recent of 432 tracked threats that use T1070.

- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)](https://intel.threadlinqs.com/threat/TL-2026-2617) — critical — 2026-09-22
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident…](https://intel.threadlinqs.com/threat/TL-2026-1877) — high — 2026-08-04
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account…](https://intel.threadlinqs.com/threat/TL-2026-1872) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…](https://intel.threadlinqs.com/threat/TL-2026-1790) — critical — 2026-07-31
- [SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD](https://intel.threadlinqs.com/threat/TL-2026-1787) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and…](https://intel.threadlinqs.com/threat/TL-2026-1780) — critical — 2026-07-31
- [PamDOORa: Commercialized PAM-Abuse Backdoor for SSH Credential Theft on Linux — Evolution of the Plague /…](https://intel.threadlinqs.com/threat/TL-2026-1772) — high — 2026-07-30
- [Russian TA488 (Void Blizzard / Laundry Bear) Exploits Exchange OWA Zero-Day (CVE-2026-42897) with OWAReaper…](https://intel.threadlinqs.com/threat/TL-2026-1763) — critical — 2026-07-29
- [CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memory](https://intel.threadlinqs.com/threat/TL-2026-1762) — critical — 2026-07-29
- [Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…](https://intel.threadlinqs.com/threat/TL-2026-1760) — critical — 2026-07-29
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force](https://intel.threadlinqs.com/threat/TL-2026-1758) — high — 2026-07-29
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan](https://intel.threadlinqs.com/threat/TL-2026-1746) — critical — 2026-07-28
- [Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process](https://intel.threadlinqs.com/threat/TL-2026-1745) — high — 2026-07-28
- [Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and…](https://intel.threadlinqs.com/threat/TL-2026-1741) — high — 2026-07-28
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27

## Related CVEs

CVEs referenced by the tracked threats that use T1070, most frequent first.

- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)

## Detection coverage

Threadlinqs maintains 150 detection rules mapped to T1070 (SPL 39, KQL 48, Sigma 63). Rule content is available to Blue tier accounts and above; this page shows counts only.

150 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1070.001 Clear Windows Event Logs — 4 tracked threats
- T1070.002 Clear Linux or Mac System Logs — 6 tracked threats
- [T1070.003 Clear Command History](https://intel.threadlinqs.com/technique/T1070.003) — 21 tracked threats
- [T1070.004 File Deletion](https://intel.threadlinqs.com/technique/T1070.004) — 207 tracked threats
- T1070.005 Network Share Connection Removal — 1 tracked threat
- [T1070.006 Timestomp](https://intel.threadlinqs.com/technique/T1070.006) — 37 tracked threats
- T1070.007 Clear Network Connection History and Configurations — 2 tracked threats
- T1070.008 Clear Mailbox Data — 4 tracked threats
- T1070.009 Clear Persistence — 6 tracked threats
- T1070.010 Relocate Malware — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1070
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
