Activity timeline
T1491.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1491.001 Internal Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1491 Defacement. Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 6 critical, 7 high, 6 medium.
Threats that use T1491.001 most often also use T1005 Data from Local System (12 threats), T1190 Exploit Public-Facing Application (11 threats), T1657 Financial Theft (10 threats), T1071.001 Web Protocols (9 threats), T1083 File and Directory Discovery (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
12 tracked threat actors appear in the threats that use T1491.001; the most frequent are ShinyHunters (4), ALPHV (1), Anubis (1), BlackCat (1), Gamaredon Group (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1491.001.
Data sources
Telemetry that can reveal T1491.001, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
19 tracked threats use T1491.001.
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…high
- Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…critical
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…high
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…high
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrationshigh
- Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…medium
- AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)medium
- Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photosmedium
- InfernoGrabber v9.0: AI-Generated In-Browser Ransomware Abusing the Chromium File System Access APImedium
- Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)critical
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…critical
- Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…critical
- ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portalmedium
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…critical
Detection coverage
Threadlinqs maintains 32 detection rules mapped to T1491.001 (SPL 8, KQL 7, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1491 Defacement — 73 tracked threats at the technique level.