# T1560.001 Archive via Utility

> As of 2026-10-05, T1560.001 (Archive via Utility) appears in 63 tracked threats, first reported 2026-02-16 and most recently 2026-10-03, with linked actors including APT28, Akira, Storm-1567; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 63 (14 critical, 42 high, 6 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-03
- **Threat actors:** 28
- **Detection rules:** 123 (counts only; Blue tier and above)

## Key facts

- **ID:** T1560.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Parent:** T1560
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1560/001/

## Activity timeline

T1560.001 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 19 reports, and 63 of the 63 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1560.001 Archive via Utility is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix, as a sub-technique of [T1560 Archive Collected Data](https://intel.threadlinqs.com/technique/T1560). Threadlinqs maps 63 of 2623 tracked threats (2.4%) to it; by severity that is 14 critical, 42 high, 6 medium.

Threats that use T1560.001 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (47 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (44 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (41 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (37 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (36 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

28 tracked threat actors appear in the threats that use T1560.001; the most frequent are [APT28](https://intel.threadlinqs.com/actor/APT28) (3), [Akira](https://intel.threadlinqs.com/actor/Akira) (3), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (3), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (3), [APT38](https://intel.threadlinqs.com/actor/APT38) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1560.001.

- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1560.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Creation
- Process — Process Creation

## Threat actors using it

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 3
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 3
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 3
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 2
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 2

## Tracked threats

The 30 most recent of 63 tracked threats that use T1560.001.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2599) — high — 2026-09-21
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…](https://intel.threadlinqs.com/threat/TL-2026-2192) — high — 2026-08-28
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…](https://intel.threadlinqs.com/threat/TL-2026-2160) — 2026-08-25
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender](https://intel.threadlinqs.com/threat/TL-2026-2062) — high — 2026-08-12
- [Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1914) — high — 2026-08-06
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync…](https://intel.threadlinqs.com/threat/TL-2026-1894) — high — 2026-08-05
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — medium — 2026-07-29
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol](https://intel.threadlinqs.com/threat/TL-2026-1747) — critical — 2026-07-28
- [SafePay Ransomware Abuses OneDrive Sync Client for Covert Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-1728) — high — 2026-07-27
- [Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom](https://intel.threadlinqs.com/threat/TL-2026-1642) — medium — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering…](https://intel.threadlinqs.com/threat/TL-2026-1551) — high — 2026-07-19
- [CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)](https://intel.threadlinqs.com/threat/TL-2026-1470) — medium — 2026-07-18
- [CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Execution](https://intel.threadlinqs.com/threat/TL-2026-1428) — high — 2026-07-16

## Related CVEs

CVEs referenced by the tracked threats that use T1560.001, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-54068](https://intel.threadlinqs.com/cve/CVE-2025-54068)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-35616](https://intel.threadlinqs.com/cve/CVE-2026-35616)
- [CVE-2026-63077](https://intel.threadlinqs.com/cve/CVE-2026-63077)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)
- [CVE-2026-66014](https://intel.threadlinqs.com/cve/CVE-2026-66014)

## Detection coverage

Threadlinqs maintains 123 detection rules mapped to T1560.001 (SPL 38, KQL 38, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.

123 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1560 Archive Collected Data](https://intel.threadlinqs.com/technique/T1560) — 224 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1560.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
