Activity timeline
T1561 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 10 reports, and 35 of the 35 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1561 Disk Wipe is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 25 critical, 8 high, 1 medium.
Threats that use T1561 most often also use T1059 Command and Scripting Interpreter (28 threats), T1027 Obfuscated Files or Information (22 threats), T1071 Application Layer Protocol (22 threats), T1485 Data Destruction (22 threats), T1005 Data from Local System (21 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
30 tracked threat actors appear in the threats that use T1561; the most frequent are TeamPCP (5), Handala Hack (4), Sandworm (4), Void Manticore (4), Handala (3).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1561.
Data sources
Telemetry that can reveal T1561, per MITRE ATT&CK.
- Command — Command Execution
- Drive — Drive Access, Drive Modification
- Driver — Driver Load
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 35 tracked threats that use T1561.
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC
- Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…high
- Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path…critical
- FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable…high
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…high
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…high
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2…critical
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…high
- JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…critical
- GuardFall: Shell-Injection Guardrail Bypass Exposes Open-Source AI Coding Agents to Supply-Chain Attackshigh
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdowncritical
- Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakeningcritical
- CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEMcritical
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitationcritical
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…critical
- Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Deliverycritical
- TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)critical
- NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National…medium
- Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilitieshigh
- durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK…critical
- GitHub Internal Breach — TeamPCP Exfiltrates 3,800+ Repos via Poisoned VS Code Extension Tied to Mini…critical
- VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data…critical
- TeamPCP Cascading Supply Chain Campaign: Telnyx PyPI Compromise with WAV Steganographycritical
- Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker…critical
- Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device…critical
- Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attackcritical
- Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaigncritical
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with…critical
- Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and…critical
Detection coverage
Threadlinqs maintains 20 detection rules mapped to T1561 (SPL 7, KQL 5, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1561.001 Disk Content Wipe — 10 tracked threats
- T1561.002 Disk Structure Wipe — 3 tracked threats