# T1485 Data Destruction

> As of 2026-10-05, T1485 (Data Destruction) appears in 194 tracked threats, first reported 2022-04-07 and most recently 2026-10-03, with linked actors including TeamPCP, Sandworm, Static Tundra; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 194 (100 critical, 65 high, 19 medium, 4 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-03
- **Threat actors:** 68
- **Detection rules:** 221 (counts only; Blue tier and above)

## Key facts

- **ID:** T1485
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1485/

## Activity timeline

T1485 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 61 reports, and 193 of the 194 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1485 Data Destruction is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 194 of 2623 tracked threats (7.4%) to it; by severity that is 100 critical, 65 high, 19 medium, 4 low.

Threats that use T1485 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (113 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (107 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (99 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (92 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (91 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

68 tracked threat actors appear in the threats that use T1485; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (18), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (7), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (7), [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) (6), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (5).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1485.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1485, per MITRE ATT&CK.

- Cloud Storage — Cloud Storage Deletion, Cloud Storage Modification
- Command — Command Execution
- File — File Deletion, File Modification
- Image — Image Deletion
- Instance — Instance Deletion
- Process — Process Creation
- Snapshot — Snapshot Deletion
- Volume — Volume Deletion

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 18
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 7
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 7
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 6
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 5
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 5
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 4
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 4
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [VECT](https://intel.threadlinqs.com/actor/VECT) — 4

## Tracked threats

The 30 most recent of 194 tracked threats that use T1485.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…](https://intel.threadlinqs.com/threat/TL-2026-2880) — high — 2026-10-03
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses…](https://intel.threadlinqs.com/threat/TL-2026-2653) — critical — 2026-09-25
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2475) — critical — 2026-09-13
- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — critical — 2026-09-06
- [ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…](https://intel.threadlinqs.com/threat/TL-2026-2195) — critical — 2026-08-28
- [Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchains](https://intel.threadlinqs.com/threat/TL-2026-2194) — critical — 2026-08-28
- [Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…](https://intel.threadlinqs.com/threat/TL-2026-2152) — critical — 2026-08-26
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22
- [SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targeting](https://intel.threadlinqs.com/threat/TL-2026-2104) — high — 2026-08-21
- [SilkParasite: China-Nexus Cyber Espionage Campaign Targeting Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2090) — critical — 2026-08-20
- [Critical Type Confusion in isolated-vm ExternalCopy Enables Guest-to-Host Sandbox Escape and RCE…](https://intel.threadlinqs.com/threat/TL-2026-2084) — critical — 2026-08-20
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including…](https://intel.threadlinqs.com/threat/TL-2026-2064) — critical — 2026-08-18
- [Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…](https://intel.threadlinqs.com/threat/TL-2026-2048) — critical — 2026-08-17
- [Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables…](https://intel.threadlinqs.com/threat/TL-2026-2035) — critical — 2026-08-16
- [White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal…](https://intel.threadlinqs.com/threat/TL-2026-2012) — 2026-08-13
- [Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw](https://intel.threadlinqs.com/threat/TL-2026-1965) — medium — 2026-08-10
- [City of Coweta, Oklahoma Hit by Anubis Ransomware Attack](https://intel.threadlinqs.com/threat/TL-2026-1948) — high — 2026-08-09
- [Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB…](https://intel.threadlinqs.com/threat/TL-2026-1916) — high — 2026-08-06

## Related CVEs

CVEs referenced by the tracked threats that use T1485, most frequent first.

- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-4346](https://intel.threadlinqs.com/cve/CVE-2023-4346)

## Detection coverage

Threadlinqs maintains 221 detection rules mapped to T1485 (SPL 67, KQL 53, Sigma 101). Rule content is available to Blue tier accounts and above; this page shows counts only.

221 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1485.001 Lifecycle-Triggered Deletion — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1485
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
