Activity timeline
T1486 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 143 reports, and 294 of the 295 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1486 Data Encrypted for Impact is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 295 of 2623 tracked threats (11.2%) to it; by severity that is 108 critical, 143 high, 38 medium, 2 low.
Threats that use T1486 most often also use T1685 Disable or Modify Tools (180 threats), T1059 Command and Scripting Interpreter (169 threats), T1190 Exploit Public-Facing Application (168 threats), T1078 Valid Accounts (166 threats), T1082 System Information Discovery (159 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
99 tracked threat actors appear in the threats that use T1486; the most frequent are The Gentlemen (9), LockBit (8), Qilin (8), Scattered Spider (8), APT38 (7).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1486.
Data sources
Telemetry that can reveal T1486, per MITRE ATT&CK.
- Cloud Storage — Cloud Storage Modification
- Command — Command Execution
- File — File Creation, File Modification
- Network Share — Network Share Access
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 295 tracked threats that use T1486.
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)critical
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeovercritical
- NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skillslow
- Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…medium
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…high
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXihigh
- Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…critical
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groupsmedium
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…high
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Accessmedium
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…critical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…high
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storagehigh
- Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectivenessmedium
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaShigh
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…medium
- Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refusedmedium
- DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…critical
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2high
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edgehigh
Detection coverage
Threadlinqs maintains 359 detection rules mapped to T1486 (SPL 97, KQL 87, Sigma 171, other 4). Rule content is available to Blue tier accounts and above; this page shows counts only.