# T1491.002 External Defacement

> As of 2026-10-05, T1491.002 (External Defacement) appears in 24 tracked threats, first reported 2026-02-21 and most recently 2026-09-28, with linked actors including ShinyHunters, NoName057(16), APT44; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 24 (12 critical, 8 high, 3 medium)
- **First seen:** 2026-02-21
- **Last seen:** 2026-09-28
- **Threat actors:** 8
- **Detection rules:** 23 (counts only; Blue tier and above)

## Key facts

- **ID:** T1491.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1491
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1491/002/

## Activity timeline

T1491.002 first appeared in tracked threats on 2026-02-21 and was most recently reported on 2026-09-28. The busiest month was 2026-07 with 11 reports, and 24 of the 24 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1491.002 External Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1491 Defacement](https://intel.threadlinqs.com/technique/T1491). Threadlinqs maps 24 of 2623 tracked threats (0.9%) to it; by severity that is 12 critical, 8 high, 3 medium.

Threats that use T1491.002 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (16 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (16 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (15 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (13 threats), [T1505.003 Web Shell](https://intel.threadlinqs.com/technique/T1505.003) (13 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1491.002; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (6), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (2), [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (1), [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1491.002.

- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1491.002, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 6
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 1
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 1

## Tracked threats

24 tracked threats use T1491.002.

- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution](https://intel.threadlinqs.com/threat/TL-2026-2177) — critical — 2026-08-28
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive…](https://intel.threadlinqs.com/threat/TL-2026-1614) — medium — 2026-07-21
- [CVE-2026-57309: Unauthenticated Blind SQL Injection in Windu CMS 4.1 (with CVE-2026-57310 Weak Password…](https://intel.threadlinqs.com/threat/TL-2026-1568) — high — 2026-07-20
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499…](https://intel.threadlinqs.com/threat/TL-2026-1477) — high — 2026-07-18
- [wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released](https://intel.threadlinqs.com/threat/TL-2026-1465) — critical — 2026-07-18
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-1464) — critical — 2026-07-17
- [wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…](https://intel.threadlinqs.com/threat/TL-2026-1463) — critical — 2026-07-17
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16
- [313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…](https://intel.threadlinqs.com/threat/TL-2026-1374) — high — 2026-07-15
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [CVE-2026-48939 & CVE-2026-56291: Perfect-10 Joomla Extension Bugs (iCagenda, Balbooa Forms) Actively…](https://intel.threadlinqs.com/threat/TL-2026-1300) — critical — 2026-07-14
- [CISA KEV: Joomla iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Unrestricted File Upload Flaws…](https://intel.threadlinqs.com/threat/TL-2026-1266) — critical — 2026-07-13
- [Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites](https://intel.threadlinqs.com/threat/TL-2026-2248) — 2026-06-17
- [ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+…](https://intel.threadlinqs.com/threat/TL-2026-0779) — critical — 2026-06-11
- [LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…](https://intel.threadlinqs.com/threat/TL-2026-0565) — critical — 2026-05-22
- [BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by…](https://intel.threadlinqs.com/threat/TL-2026-0532) — high — 2026-05-19
- [ShinyHunters Breach of Instructure Canvas LMS via Free-For-Teacher Program](https://intel.threadlinqs.com/threat/TL-2026-2124) — high — 2026-05-08
- [cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0440) — critical — 2026-04-30
- [Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…](https://intel.threadlinqs.com/threat/TL-2026-0125) — critical — 2026-02-21

## Related CVEs

CVEs referenced by the tracked threats that use T1491.002, most frequent first.

- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-56291](https://intel.threadlinqs.com/cve/CVE-2026-56291)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2026-10702](https://intel.threadlinqs.com/cve/CVE-2026-10702)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42608](https://intel.threadlinqs.com/cve/CVE-2026-42608)
- [CVE-2026-48172](https://intel.threadlinqs.com/cve/CVE-2026-48172)
- [CVE-2026-57309](https://intel.threadlinqs.com/cve/CVE-2026-57309)
- [CVE-2026-57310](https://intel.threadlinqs.com/cve/CVE-2026-57310)
- [CVE-2026-57311](https://intel.threadlinqs.com/cve/CVE-2026-57311)

## Detection coverage

Threadlinqs maintains 23 detection rules mapped to T1491.002 (SPL 3, KQL 9, Sigma 11). Rule content is available to Blue tier accounts and above; this page shows counts only.

23 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1491 Defacement](https://intel.threadlinqs.com/technique/T1491) — 73 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1491.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
