Activity timeline
T1485 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 61 reports, and 193 of the 194 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1485 Data Destruction is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 194 of 2623 tracked threats (7.4%) to it; by severity that is 100 critical, 65 high, 19 medium, 4 low.
Threats that use T1485 most often also use T1059 Command and Scripting Interpreter (113 threats), T1005 Data from Local System (107 threats), T1190 Exploit Public-Facing Application (99 threats), T1078 Valid Accounts (92 threats), T1082 System Information Discovery (91 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
68 tracked threat actors appear in the threats that use T1485; the most frequent are TeamPCP (18), Sandworm (7), Static Tundra (7), Void Manticore (6), Handala Hack (5).
Mitigations
MITRE ATT&CK lists 3 mitigations for T1485.
Data sources
Telemetry that can reveal T1485, per MITRE ATT&CK.
- Cloud Storage — Cloud Storage Deletion, Cloud Storage Modification
- Command — Command Execution
- File — File Deletion, File Modification
- Image — Image Deletion
- Instance — Instance Deletion
- Process — Process Creation
- Snapshot — Snapshot Deletion
- Volume — Volume Deletion
Threat actors using it
Tracked threats
The 30 most recent of 194 tracked threats that use T1485.
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses…critical
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCEcritical
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)critical
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchainscritical
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targetinghigh
- SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governmentscritical
- Critical Type Confusion in isolated-vm ExternalCopy Enables Guest-to-Host Sandbox Escape and RCE…critical
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026medium
- Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including…critical
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables…critical
- White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal…
- Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flawmedium
- City of Coweta, Oklahoma Hit by Anubis Ransomware Attackhigh
- Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB…high
Detection coverage
Threadlinqs maintains 221 detection rules mapped to T1485 (SPL 67, KQL 53, Sigma 101). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1485.001 Lifecycle-Triggered Deletion — 0 tracked threats