Activity timeline
T1489 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 92 reports, and 220 of the 220 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1489 Service Stop is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 220 of 2623 tracked threats (8.4%) to it; by severity that is 75 critical, 123 high, 20 medium, 1 low.
Threats that use T1489 most often also use T1190 Exploit Public-Facing Application (144 threats), T1685 Disable or Modify Tools (130 threats), T1005 Data from Local System (114 threats), T1059 Command and Scripting Interpreter (111 threats), T1082 System Information Discovery (104 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
63 tracked threat actors appear in the threats that use T1489; the most frequent are The Gentlemen (7), Sandworm (5), LockBit (4), VECT (4), Andariel (3).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1489.
Data sources
Telemetry that can reveal T1489, per MITRE ATT&CK.
- Command — Command Execution
- File — File Modification
- Process — OS API Execution, Process Creation, Process Termination
- Service — Service Metadata
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 220 tracked threats that use T1489.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromisedmedium
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…critical
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Rootcritical
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Pluginhigh
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCEcritical
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…medium
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…medium
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- Multiple Zscaler Client Connector Flaws Enable Remote Code Execution (CVE-2026-59568)critical
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software…medium
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection…critical
- Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug…medium
- DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and Sessionhigh
- City of Coweta, Oklahoma Hit by Anubis Ransomware Attackhigh
Detection coverage
Threadlinqs maintains 252 detection rules mapped to T1489 (SPL 82, KQL 75, Sigma 95). Rule content is available to Blue tier accounts and above; this page shows counts only.