# T1486 Data Encrypted for Impact

> As of 2026-10-05, T1486 (Data Encrypted for Impact) appears in 295 tracked threats, first reported 2022-04-07 and most recently 2026-10-01, with linked actors including The Gentlemen, LockBit, Qilin; it most often appears alongside T1685 (Disable or Modify Tools).

- **Tracked threats:** 295 (108 critical, 143 high, 38 medium, 2 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-01
- **Threat actors:** 99
- **Detection rules:** 359 (counts only; Blue tier and above)

## Key facts

- **ID:** T1486
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1486/

## Activity timeline

T1486 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-01. The busiest month was 2026-07 with 143 reports, and 294 of the 295 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1486 Data Encrypted for Impact is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 295 of 2623 tracked threats (11.2%) to it; by severity that is 108 critical, 143 high, 38 medium, 2 low.

Threats that use T1486 most often also use [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (180 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (169 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (168 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (166 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (159 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

99 tracked threat actors appear in the threats that use T1486; the most frequent are [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (9), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (8), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (8), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (8), [APT38](https://intel.threadlinqs.com/actor/APT38) (7).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1486.

- [M1040 Behavior Prevention on Endpoint](https://attack.mitre.org/mitigations/M1040/)
- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1486, per MITRE ATT&CK.

- Cloud Storage — Cloud Storage Modification
- Command — Command Execution
- File — File Creation, File Modification
- Network Share — Network Share Access
- Process — Process Creation

## Threat actors using it

- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 9
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 8
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 8
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 8
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 7
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 7
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 6
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 6
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 5
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 5

## Tracked threats

The 30 most recent of 295 tracked threats that use T1486.

- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…](https://intel.threadlinqs.com/threat/TL-2026-2833) — critical — 2026-10-01
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1985) — critical — 2026-08-11
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills](https://intel.threadlinqs.com/threat/TL-2026-1828) — low — 2026-08-03
- [Sumner County Schools (TN) Network Intrusion Delays 2026-27 School Year, Scope of Data Exposure Still…](https://intel.threadlinqs.com/threat/TL-2026-1824) — medium — 2026-08-02
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…](https://intel.threadlinqs.com/threat/TL-2026-1797) — high — 2026-07-31
- [AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams…](https://intel.threadlinqs.com/threat/TL-2026-1777) — high — 2026-07-30
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — medium — 2026-07-29
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent…](https://intel.threadlinqs.com/threat/TL-2026-1734) — high — 2026-07-28
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — medium — 2026-07-27
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…](https://intel.threadlinqs.com/threat/TL-2026-1727) — high — 2026-07-27
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [BlackCat/ALPHV Ransomware Abuses Azure Storage Account Keys via Sphynx Encryptor to Mass-Encrypt Cloud Storage](https://intel.threadlinqs.com/threat/TL-2026-1712) — high — 2026-07-26
- [Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness](https://intel.threadlinqs.com/threat/TL-2026-1702) — medium — 2026-07-25
- [msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaS](https://intel.threadlinqs.com/threat/TL-2026-1694) — high — 2026-07-25
- [AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and…](https://intel.threadlinqs.com/threat/TL-2026-1686) — medium — 2026-07-25
- [Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused](https://intel.threadlinqs.com/threat/TL-2026-1683) — medium — 2026-07-25
- [DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops…](https://intel.threadlinqs.com/threat/TL-2026-1680) — critical — 2026-07-25
- [TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2](https://intel.threadlinqs.com/threat/TL-2026-1684) — high — 2026-07-23
- [Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge](https://intel.threadlinqs.com/threat/TL-2026-1663) — high — 2026-07-23

## Related CVEs

CVEs referenced by the tracked threats that use T1486, most frequent first.

- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)

## Detection coverage

Threadlinqs maintains 359 detection rules mapped to T1486 (SPL 97, KQL 87, Sigma 171, other 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

359 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1486
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
