Activity timeline
T1491 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 23 reports, and 73 of the 73 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1491 Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 73 of 2623 tracked threats (2.8%) to it; by severity that is 37 critical, 30 high, 5 medium.
Threats that use T1491 most often also use T1059 Command and Scripting Interpreter (50 threats), T1190 Exploit Public-Facing Application (47 threats), T1036 Masquerading (43 threats), T1005 Data from Local System (41 threats), T1078 Valid Accounts (40 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
43 tracked threat actors appear in the threats that use T1491; the most frequent are ShinyHunters (4), TeamPCP (4), Cyber Av3ngers (3), UNC6240 (3), Black Basta (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1491.
Data sources
Telemetry that can reveal T1491, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 73 tracked threats that use T1491.
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…high
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…critical
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic…high
- CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS…high
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…high
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…critical
- "Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh /…high
- Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M…high
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…critical
- CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws…critical
- Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military…high
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days…critical
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
- Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo…high
- CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions — iCagenda (CVE-2026-48939) and Balbooa…critical
- Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian…high
- Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)critical
- Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File…critical
- python.org Release Management API Authentication Bypass (Patched, No Exploitation Confirmed)high
- Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshellscritical
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…high
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2…critical
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)critical
- Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat…medium
- Blackfield (BlackFL) Ransomware Demands $2 Million from Nidec Chaun-Choung Technology Corporation (Nidec…high
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdowncritical
- Synology MailPlus Server Critical Remote Code Execution and Arbitrary File Access (CVE-2026-13136…critical
Detection coverage
Threadlinqs maintains 12 detection rules mapped to T1491 (SPL 4, KQL 2, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1491.001 Internal Defacement — 19 tracked threats
- T1491.002 External Defacement — 24 tracked threats