Activity timeline
T1560.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 19 reports, and 63 of the 63 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1560.001 Archive via Utility is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of T1560 Archive Collected Data. Threadlinqs maps 63 of 2623 tracked threats (2.4%) to it; by severity that is 14 critical, 42 high, 6 medium.
Threats that use T1560.001 most often also use T1005 Data from Local System (47 threats), T1071.001 Web Protocols (44 threats), T1027 Obfuscated Files or Information (41 threats), T1036.005 Match Legitimate Resource Name or Location (37 threats), T1041 Exfiltration Over C2 Channel (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
28 tracked threat actors appear in the threats that use T1560.001; the most frequent are APT28 (3), Akira (3), Storm-1567 (3), TeamPCP (3), APT38 (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1560.001.
Data sources
Telemetry that can reveal T1560.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Creation
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 63 tracked threats that use T1560.001.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoorshigh
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…medium
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Wormcritical
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defenderhigh
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscationhigh
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…high
- OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Thefthigh
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groupsmedium
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocolcritical
- SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltrationhigh
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransommedium
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…high
- CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)medium
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Executionhigh
Detection coverage
Threadlinqs maintains 123 detection rules mapped to T1560.001 (SPL 38, KQL 38, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1560 Archive Collected Data — 224 tracked threats at the technique level.