# T1561.001 Disk Content Wipe

> As of 2026-10-05, T1561.001 (Disk Content Wipe) appears in 10 tracked threats, first reported 2026-02-02 and most recently 2026-09-15, with linked actors including Static Tundra, ALPHV, BlackCat; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 10 (2 critical, 5 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-15
- **Threat actors:** 9
- **Detection rules:** 13 (counts only; Blue tier and above)

## Key facts

- **ID:** T1561.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1561
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1561/001/

## Activity timeline

T1561.001 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-15. The busiest month was 2026-07 with 5 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1561.001 Disk Content Wipe is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1561 Disk Wipe](https://intel.threadlinqs.com/technique/T1561). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 2 critical, 5 high, 3 medium.

Threats that use T1561.001 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (6 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (5 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (5 threats), [T1490 Inhibit System Recovery](https://intel.threadlinqs.com/technique/T1490) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1561.001; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) (1), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (1), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1561.001.

- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1561.001, per MITRE ATT&CK.

- Command — Command Execution
- Drive — Drive Access, Drive Modification
- Driver — Driver Load
- Process — Process Creation

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 1
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 1

## Tracked threats

10 tracked threats use T1561.001.

- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption…](https://intel.threadlinqs.com/threat/TL-2026-2154) — high — 2026-08-26
- [Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2…](https://intel.threadlinqs.com/threat/TL-2026-1729) — critical — 2026-07-27
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against…](https://intel.threadlinqs.com/threat/TL-2026-1374) — high — 2026-07-15
- [CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day](https://intel.threadlinqs.com/threat/TL-2026-1346) — medium — 2026-07-15
- [Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion…](https://intel.threadlinqs.com/threat/TL-2026-1166) — medium — 2026-07-10
- [Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…](https://intel.threadlinqs.com/threat/TL-2026-0515) — high — 2026-05-14
- [Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper](https://intel.threadlinqs.com/threat/TL-2026-0014) — critical — 2026-02-02

## Related CVEs

CVEs referenced by the tracked threats that use T1561.001, most frequent first.

- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-50507](https://intel.threadlinqs.com/cve/CVE-2026-50507)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)

## Detection coverage

Threadlinqs maintains 13 detection rules mapped to T1561.001 (SPL 4, KQL 3, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

13 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1561 Disk Wipe](https://intel.threadlinqs.com/technique/T1561) — 35 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1561.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
