# T1491 Defacement

> As of 2026-10-05, T1491 (Defacement) appears in 73 tracked threats, first reported 2026-02-02 and most recently 2026-09-09, with linked actors including ShinyHunters, TeamPCP, Cyber Av3ngers; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 73 (37 critical, 30 high, 5 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-09
- **Threat actors:** 43
- **Detection rules:** 12 (counts only; Blue tier and above)

## Key facts

- **ID:** T1491
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1491/

## Activity timeline

T1491 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-09. The busiest month was 2026-07 with 23 reports, and 73 of the 73 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1491 Defacement is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 73 of 2623 tracked threats (2.8%) to it; by severity that is 37 critical, 30 high, 5 medium.

Threats that use T1491 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (50 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (47 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (43 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (41 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (40 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

43 tracked threat actors appear in the threats that use T1491; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (4), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) (3), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) (3), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1491.

- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1491, per MITRE ATT&CK.

- Application Log — Application Log Content
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 4
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 3
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 3
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 2
- [DevMan](https://intel.threadlinqs.com/actor/DevMan) — 2
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 2
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 2
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 2
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 2
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1

## Tracked threats

The 30 most recent of 73 tracked threats that use T1491.

- [Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran…](https://intel.threadlinqs.com/threat/TL-2026-2420) — high — 2026-09-09
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV…](https://intel.threadlinqs.com/threat/TL-2026-2210) — critical — 2026-08-29
- [Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic…](https://intel.threadlinqs.com/threat/TL-2026-1882) — high — 2026-08-04
- [CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS…](https://intel.threadlinqs.com/threat/TL-2026-1749) — high — 2026-07-28
- [France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1652) — high — 2026-07-23
- [Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits…](https://intel.threadlinqs.com/threat/TL-2026-1649) — critical — 2026-07-23
- ["Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh /…](https://intel.threadlinqs.com/threat/TL-2026-1491) — high — 2026-07-18
- [Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M…](https://intel.threadlinqs.com/threat/TL-2026-1476) — high — 2026-07-18
- [CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-1464) — critical — 2026-07-17
- [CISA Orders Federal Agencies to Patch Exploited Fortinet FortiSandbox Command Injection Flaws…](https://intel.threadlinqs.com/threat/TL-2026-1433) — critical — 2026-07-17
- [Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military…](https://intel.threadlinqs.com/threat/TL-2026-1417) — high — 2026-07-16
- [July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-1372) — critical — 2026-07-15
- ["Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign](https://intel.threadlinqs.com/threat/TL-2026-1356) — high — 2026-07-15
- [Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo…](https://intel.threadlinqs.com/threat/TL-2026-1294) — high — 2026-07-14
- [CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions — iCagenda (CVE-2026-48939) and Balbooa…](https://intel.threadlinqs.com/threat/TL-2026-1267) — critical — 2026-07-13
- [Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian…](https://intel.threadlinqs.com/threat/TL-2026-1265) — high — 2026-07-13
- [Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)](https://intel.threadlinqs.com/threat/TL-2026-1262) — critical — 2026-07-13
- [Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File…](https://intel.threadlinqs.com/threat/TL-2026-1254) — critical — 2026-07-13
- [python.org Release Management API Authentication Bypass (Patched, No Exploitation Confirmed)](https://intel.threadlinqs.com/threat/TL-2026-1241) — high — 2026-07-11
- [Australia (ACSC) Warns of Global Campaign Exploiting Vulnerable CMS Platforms to Deploy Webshells](https://intel.threadlinqs.com/threat/TL-2026-1224) — critical — 2026-07-11
- [GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…](https://intel.threadlinqs.com/threat/TL-2026-1167) — high — 2026-07-10
- [GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2…](https://intel.threadlinqs.com/threat/TL-2026-1158) — critical — 2026-07-10
- [GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1147) — high — 2026-07-09
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240)](https://intel.threadlinqs.com/threat/TL-2026-1094) — critical — 2026-07-03
- [Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat…](https://intel.threadlinqs.com/threat/TL-2026-1087) — medium — 2026-07-02
- [Blackfield (BlackFL) Ransomware Demands $2 Million from Nidec Chaun-Choung Technology Corporation (Nidec…](https://intel.threadlinqs.com/threat/TL-2026-1196) — high — 2026-06-30
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — critical — 2026-06-30
- [Synology MailPlus Server Critical Remote Code Execution and Arbitrary File Access (CVE-2026-13136…](https://intel.threadlinqs.com/threat/TL-2026-1014) — critical — 2026-06-30

## Related CVEs

CVEs referenced by the tracked threats that use T1491, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-56291](https://intel.threadlinqs.com/cve/CVE-2026-56291)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32432](https://intel.threadlinqs.com/cve/CVE-2025-32432)

## Detection coverage

Threadlinqs maintains 12 detection rules mapped to T1491 (SPL 4, KQL 2, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

12 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1491.001 Internal Defacement](https://intel.threadlinqs.com/technique/T1491.001) — 19 tracked threats
- [T1491.002 External Defacement](https://intel.threadlinqs.com/technique/T1491.002) — 24 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1491
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
