Activity timeline
T1490 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 80 reports, and 219 of the 220 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1490 Inhibit System Recovery is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 220 of 2623 tracked threats (8.4%) to it; by severity that is 72 critical, 122 high, 20 medium, 2 low.
Threats that use T1490 most often also use T1486 Data Encrypted for Impact (153 threats), T1685 Disable or Modify Tools (153 threats), T1078 Valid Accounts (134 threats), T1190 Exploit Public-Facing Application (124 threats), T1059 Command and Scripting Interpreter (116 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
84 tracked threat actors appear in the threats that use T1490; the most frequent are Qilin (10), The Gentlemen (9), ALPHV (7), Akira (6), BlackCat (6).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1490.
Data sources
Telemetry that can reveal T1490, per MITRE ATT&CK.
- Cloud Storage — Cloud Storage Deletion
- Command — Command Execution
- File — File Deletion
- Process — Process Creation
- Service — Service Metadata
- Snapshot — Snapshot Deletion
- Windows Registry — Windows Registry Key Modification
Threat actors using it
Tracked threats
The 30 most recent of 220 tracked threats that use T1490.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- City of Vicksburg, Mississippi shuts down systems after ransomware attackmedium
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansashigh
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…high
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Thefthigh
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypasshigh
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…medium
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…high
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…high
- Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…high
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)high
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Electionhigh
Detection coverage
Threadlinqs maintains 296 detection rules mapped to T1490 (SPL 102, KQL 74, Sigma 119, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.