Threadlinqs IntelligenceStart free

ATT&CK techniqueImpact

T1489 Service Stop

ImpactEnterprise

As of 2026-10-05, T1489 (Service Stop) appears in 220 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including The Gentlemen, Sandworm, LockBit; it most often appears alongside T1190 (Exploit Public-Facing Application).

Tracked threats
22075 critical, 123 high, 20 medium, 1 low
First seen
2026-02-02
Last seen
2026-10-03
Threat actors
63In the threats using it
Detection rules
252Blue tier and above

Data as of:

Activity timeline

T1489 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 92 reports, and 220 of the 220 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1489 Service Stop is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 220 of 2623 tracked threats (8.4%) to it; by severity that is 75 critical, 123 high, 20 medium, 1 low.

Threats that use T1489 most often also use T1190 Exploit Public-Facing Application (144 threats), T1685 Disable or Modify Tools (130 threats), T1005 Data from Local System (114 threats), T1059 Command and Scripting Interpreter (111 threats), T1082 System Information Discovery (104 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

63 tracked threat actors appear in the threats that use T1489; the most frequent are The Gentlemen (7), Sandworm (5), LockBit (4), VECT (4), Andariel (3).

Mitigations

MITRE ATT&CK lists 5 mitigations for T1489.

Data sources

Telemetry that can reveal T1489, per MITRE ATT&CK.

  • Command — Command Execution
  • File — File Modification
  • Process — OS API Execution, Process Creation, Process Termination
  • Service — Service Metadata
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 220 tracked threats that use T1489.

Detection coverage

Threadlinqs maintains 252 detection rules mapped to T1489 (SPL 82, KQL 75, Sigma 95). Rule content is available to Blue tier accounts and above; this page shows counts only.

252 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans