Threadlinqs IntelligenceStart free

ATT&CK techniqueImpact

T1490 Inhibit System Recovery

ImpactEnterprise

As of 2026-10-05, T1490 (Inhibit System Recovery) appears in 220 tracked threats, first reported 2022-04-07 and most recently 2026-10-03, with linked actors including Qilin, The Gentlemen, ALPHV; it most often appears alongside T1486 (Data Encrypted for Impact).

Tracked threats
22072 critical, 122 high, 20 medium, 2 low
First seen
2022-04-07
Last seen
2026-10-03
Threat actors
84In the threats using it
Detection rules
296Blue tier and above

Data as of:

Activity timeline

T1490 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 80 reports, and 219 of the 220 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1490 Inhibit System Recovery is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 220 of 2623 tracked threats (8.4%) to it; by severity that is 72 critical, 122 high, 20 medium, 2 low.

Threats that use T1490 most often also use T1486 Data Encrypted for Impact (153 threats), T1685 Disable or Modify Tools (153 threats), T1078 Valid Accounts (134 threats), T1190 Exploit Public-Facing Application (124 threats), T1059 Command and Scripting Interpreter (116 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

84 tracked threat actors appear in the threats that use T1490; the most frequent are Qilin (10), The Gentlemen (9), ALPHV (7), Akira (6), BlackCat (6).

Mitigations

MITRE ATT&CK lists 4 mitigations for T1490.

Data sources

Telemetry that can reveal T1490, per MITRE ATT&CK.

  • Cloud Storage — Cloud Storage Deletion
  • Command — Command Execution
  • File — File Deletion
  • Process — Process Creation
  • Service — Service Metadata
  • Snapshot — Snapshot Deletion
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 220 tracked threats that use T1490.

Detection coverage

Threadlinqs maintains 296 detection rules mapped to T1490 (SPL 102, KQL 74, Sigma 119, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

296 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans