# T1491.001 Internal Defacement

> As of 2026-10-05, T1491.001 (Internal Defacement) appears in 19 tracked threats, first reported 2026-02-05 and most recently 2026-09-26, with linked actors including ShinyHunters, ALPHV, Anubis; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 19 (6 critical, 7 high, 6 medium)
- **First seen:** 2026-02-05
- **Last seen:** 2026-09-26
- **Threat actors:** 12
- **Detection rules:** 32 (counts only; Blue tier and above)

## Key facts

- **ID:** T1491.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1491
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1491/001/

## Activity timeline

T1491.001 first appeared in tracked threats on 2026-02-05 and was most recently reported on 2026-09-26. The busiest month was 2026-07 with 11 reports, and 19 of the 19 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1491.001 Internal Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1491 Defacement](https://intel.threadlinqs.com/technique/T1491). Threadlinqs maps 19 of 2623 tracked threats (0.7%) to it; by severity that is 6 critical, 7 high, 6 medium.

Threats that use T1491.001 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (12 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (11 threats), [T1657 Financial Theft](https://intel.threadlinqs.com/technique/T1657) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (9 threats), [T1083 File and Directory Discovery](https://intel.threadlinqs.com/technique/T1083) (9 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

12 tracked threat actors appear in the threats that use T1491.001; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [Anubis](https://intel.threadlinqs.com/actor/Anubis) (1), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (1), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1491.001.

- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1491.001, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [MedusaLocker](https://intel.threadlinqs.com/actor/MedusaLocker) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 1
- [Warlock](https://intel.threadlinqs.com/actor/Warlock) — 1

## Tracked threats

19 tracked threats use T1491.001.

- [Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…](https://intel.threadlinqs.com/threat/TL-2026-2672) — high — 2026-09-26
- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [AnMed Health Ransomware/Malware Disruption Closes 79-83 South Carolina/Georgia Facilities, Extortion Note…](https://intel.threadlinqs.com/threat/TL-2026-1727) — high — 2026-07-27
- [Instructure Canvas Breach (ShinyHunters) Drives 58% of H1 2026 Data Breach Notices — 275M Records, 8,809…](https://intel.threadlinqs.com/threat/TL-2026-1705) — critical — 2026-07-26
- [Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary…](https://intel.threadlinqs.com/threat/TL-2026-1615) — high — 2026-07-22
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and…](https://intel.threadlinqs.com/threat/TL-2026-1347) — high — 2026-07-15
- [ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations](https://intel.threadlinqs.com/threat/TL-2026-1275) — high — 2026-07-13
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…](https://intel.threadlinqs.com/threat/TL-2026-1166) — medium — 2026-07-10
- [AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek)](https://intel.threadlinqs.com/threat/TL-2026-1129) — medium — 2026-07-05
- [Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photos](https://intel.threadlinqs.com/threat/TL-2026-1119) — medium — 2026-07-05
- [InfernoGrabber v9.0: AI-Generated In-Browser Ransomware Abusing the Chromium File System Access API](https://intel.threadlinqs.com/threat/TL-2026-1051) — medium — 2026-07-01
- [Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0800) — critical — 2026-06-15
- [ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…](https://intel.threadlinqs.com/threat/TL-2026-0779) — critical — 2026-06-11
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [ZETARINK Ransomware v1.22 — Go-Based File Encryption with Garble Obfuscation and Tor Recovery Portal](https://intel.threadlinqs.com/threat/TL-2026-0086) — medium — 2026-02-15
- [SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub…](https://intel.threadlinqs.com/threat/TL-2026-0103) — critical — 2026-02-05

## Related CVEs

CVEs referenced by the tracked threats that use T1491.001, most frequent first.

- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-23760](https://intel.threadlinqs.com/cve/CVE-2026-23760)
- [CVE-2026-24423](https://intel.threadlinqs.com/cve/CVE-2026-24423)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-62062](https://intel.threadlinqs.com/cve/CVE-2026-62062)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)

## Detection coverage

Threadlinqs maintains 32 detection rules mapped to T1491.001 (SPL 8, KQL 7, Sigma 17). Rule content is available to Blue tier accounts and above; this page shows counts only.

32 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1491 Defacement](https://intel.threadlinqs.com/technique/T1491) — 73 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1491.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
