# T1490 Inhibit System Recovery

> As of 2026-10-05, T1490 (Inhibit System Recovery) appears in 220 tracked threats, first reported 2022-04-07 and most recently 2026-10-03, with linked actors including Qilin, The Gentlemen, ALPHV; it most often appears alongside T1486 (Data Encrypted for Impact).

- **Tracked threats:** 220 (72 critical, 122 high, 20 medium, 2 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-03
- **Threat actors:** 84
- **Detection rules:** 296 (counts only; Blue tier and above)

## Key facts

- **ID:** T1490
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1490/

## Activity timeline

T1490 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 80 reports, and 219 of the 220 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1490 Inhibit System Recovery is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 220 of 2623 tracked threats (8.4%) to it; by severity that is 72 critical, 122 high, 20 medium, 2 low.

Threats that use T1490 most often also use [T1486 Data Encrypted for Impact](https://intel.threadlinqs.com/technique/T1486) (153 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (153 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (134 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (124 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (116 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

84 tracked threat actors appear in the threats that use T1490; the most frequent are [Qilin](https://intel.threadlinqs.com/actor/Qilin) (10), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (9), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (7), [Akira](https://intel.threadlinqs.com/actor/Akira) (6), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (6).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1490.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1490, per MITRE ATT&CK.

- Cloud Storage — Cloud Storage Deletion
- Command — Command Execution
- File — File Deletion
- Process — Process Creation
- Service — Service Metadata
- Snapshot — Snapshot Deletion
- Windows Registry — Windows Registry Key Modification

## Threat actors using it

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 10
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 9
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 7
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 6
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 6
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 5
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 5
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 5
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 5
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 4
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4

## Tracked threats

The 30 most recent of 220 tracked threats that use T1490.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [City of Vicksburg, Mississippi shuts down systems after ransomware attack](https://intel.threadlinqs.com/threat/TL-2026-2862) — medium — 2026-10-02
- [Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group](https://intel.threadlinqs.com/threat/TL-2026-2829) — high — 2026-10-01
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…](https://intel.threadlinqs.com/threat/TL-2026-2773) — high — 2026-09-29
- [ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…](https://intel.threadlinqs.com/threat/TL-2026-2730) — high — 2026-09-28
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas](https://intel.threadlinqs.com/threat/TL-2026-2571) — high — 2026-09-18
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…](https://intel.threadlinqs.com/threat/TL-2026-2542) — critical — 2026-09-16
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2505) — high — 2026-09-14
- [Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass](https://intel.threadlinqs.com/threat/TL-2026-2481) — high — 2026-09-13
- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data…](https://intel.threadlinqs.com/threat/TL-2026-2352) — medium — 2026-09-06
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor…](https://intel.threadlinqs.com/threat/TL-2026-2283) — high — 2026-09-01
- [Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…](https://intel.threadlinqs.com/threat/TL-2026-2278) — high — 2026-09-01
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)](https://intel.threadlinqs.com/threat/TL-2026-2212) — high — 2026-08-29
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — high — 2026-08-29

## Related CVEs

CVEs referenced by the tracked threats that use T1490, most frequent first.

- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-27198](https://intel.threadlinqs.com/cve/CVE-2024-27198)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)

## Detection coverage

Threadlinqs maintains 296 detection rules mapped to T1490 (SPL 102, KQL 74, Sigma 119, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

296 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1490
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
