Activity timeline
T1491.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 11 reports, and 24 of the 24 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1491.002 External Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of T1491 Defacement. Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 12 critical, 8 high, 3 medium.
Threats that use T1491.002 most often also use T1005 Data from Local System (16 threats), T1190 Exploit Public-Facing Application (16 threats), T1071.001 Web Protocols (15 threats), T1059 Command and Scripting Interpreter (13 threats), T1505.003 Web Shell (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1491.002; the most frequent are ShinyHunters (6), NoName057(16) (2), APT44 (1), Handala Hack (1), Handala Hack Team (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1491.002.
Data sources
Telemetry that can reveal T1491.002, per MITRE ATT&CK.
- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
24 tracked threats use T1491.002.
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…high
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…medium
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Executioncritical
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…high
- Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive…medium
- CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…high
- IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…high
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Releasedcritical
- CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…critical
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…high
- 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…high
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- CVE-2026-48939 & CVE-2026-56291: Perfect-10 Joomla Extension Bugs (iCagenda, Balbooa Forms) Actively…critical
- CISA KEV: Joomla iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Unrestricted File Upload Flaws…critical
- Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…critical
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
- BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…high
- ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Programhigh
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEVcritical
- Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…critical
Detection coverage
Threadlinqs maintains 23 detection rules mapped to T1491.002 (SPL 3, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1491 Defacement — 73 tracked threats at the technique level.