# T1561 Disk Wipe

> As of 2026-10-05, T1561 (Disk Wipe) appears in 35 tracked threats, first reported 2026-02-02 and most recently 2026-09-17, with linked actors including TeamPCP, Handala Hack, Sandworm; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 35 (25 critical, 8 high, 1 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-09-17
- **Threat actors:** 30
- **Detection rules:** 20 (counts only; Blue tier and above)

## Key facts

- **ID:** T1561
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1561/

## Activity timeline

T1561 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-09-17. The busiest month was 2026-06 with 10 reports, and 35 of the 35 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1561 Disk Wipe is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 25 critical, 8 high, 1 medium.

Threats that use T1561 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (28 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (22 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (22 threats), [T1485 Data Destruction](https://intel.threadlinqs.com/technique/T1485) (22 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (21 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

30 tracked threat actors appear in the threats that use T1561; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (5), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) (4), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (4), [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) (4), [Handala](https://intel.threadlinqs.com/actor/Handala) (3).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1561.

- [M1053 Data Backup](https://attack.mitre.org/mitigations/M1053/)

## Data sources

Telemetry that can reveal T1561, per MITRE ATT&CK.

- Command — Command Execution
- Drive — Drive Access, Drive Modification
- Driver — Driver Load
- Process — Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 5
- [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack) — 4
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 4
- [Void Manticore](https://intel.threadlinqs.com/actor/Void%20Manticore) — 4
- [Handala](https://intel.threadlinqs.com/actor/Handala) — 3
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 3
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 3
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 3
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT29](https://intel.threadlinqs.com/actor/APT29) — 1

## Tracked threats

The 30 most recent of 35 tracked threats that use T1561.

- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Google GTIG Adopts Two-Word Threat Actor Naming Taxonomy — Sandworm/APT44 Redesignated SANDWORM RELIC](https://intel.threadlinqs.com/threat/TL-2026-1730) — 2026-07-27
- [Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2…](https://intel.threadlinqs.com/threat/TL-2026-1496) — high — 2026-07-18
- [Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path…](https://intel.threadlinqs.com/threat/TL-2026-1371) — critical — 2026-07-15
- [FSB Centre 16 (Berserk Bear/Energetic Bear) targets global critical national infrastructure via vulnerable…](https://intel.threadlinqs.com/threat/TL-2026-2375) — high — 2026-07-13
- [FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and…](https://intel.threadlinqs.com/threat/TL-2026-1283) — high — 2026-07-13
- [GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot…](https://intel.threadlinqs.com/threat/TL-2026-1167) — high — 2026-07-10
- [GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2…](https://intel.threadlinqs.com/threat/TL-2026-1158) — critical — 2026-07-10
- [GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1147) — high — 2026-07-09
- [JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248)…](https://intel.threadlinqs.com/threat/TL-2026-1044) — critical — 2026-07-01
- [GuardFall: Shell-Injection Guardrail Bypass Exposes Open-Source AI Coding Agents to Supply-Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-1131) — high — 2026-06-30
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — critical — 2026-06-30
- [Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening](https://intel.threadlinqs.com/threat/TL-2026-1008) — critical — 2026-06-30
- [CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEM](https://intel.threadlinqs.com/threat/TL-2026-1007) — critical — 2026-06-30
- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — critical — 2026-06-30
- [CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via…](https://intel.threadlinqs.com/threat/TL-2026-1000) — critical — 2026-06-30
- [Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Delivery](https://intel.threadlinqs.com/threat/TL-2026-0989) — critical — 2026-06-28
- [TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)](https://intel.threadlinqs.com/threat/TL-2026-0981) — critical — 2026-06-28
- [NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National…](https://intel.threadlinqs.com/threat/TL-2026-2239) — medium — 2026-06-17
- [Meow Mac Stealer RAT: macOS ClickFix Lures Deploy AppleScript Infostealer with Persistent RAT Capabilities](https://intel.threadlinqs.com/threat/TL-2026-0842) — high — 2026-06-17
- [durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK…](https://intel.threadlinqs.com/threat/TL-2026-0580) — critical — 2026-05-25
- [GitHub Internal Breach — TeamPCP Exfiltrates 3,800+ Repos via Poisoned VS Code Extension Tied to Mini…](https://intel.threadlinqs.com/threat/TL-2026-0536) — critical — 2026-05-20
- [VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data…](https://intel.threadlinqs.com/threat/TL-2026-0432) — critical — 2026-04-28
- [TeamPCP Cascading Supply Chain Campaign: Telnyx PyPI Compromise with WAV Steganography](https://intel.threadlinqs.com/threat/TL-2026-0299) — critical — 2026-03-30
- [Handala (Void Manticore/MOIS) Abuses Microsoft Entra ID and Intune for Mass Device Wiping at Stryker…](https://intel.threadlinqs.com/threat/TL-2026-0268) — critical — 2026-03-22
- [Iranian APT Identity Weaponization: Void Manticore/Handala Abuses Microsoft Intune MDM for Mass Device…](https://intel.threadlinqs.com/threat/TL-2026-0237) — critical — 2026-03-16
- [Handala Hack (Void Manticore) Wiper Campaign via Microsoft Intune Abuse — Stryker Attack](https://intel.threadlinqs.com/threat/TL-2026-0220) — critical — 2026-03-12
- [Iranian MOIS Actors Leveraging Cybercrime Ecosystem — Void Manticore & MuddyWater Campaign](https://intel.threadlinqs.com/threat/TL-2026-0215) — critical — 2026-03-12
- [Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with…](https://intel.threadlinqs.com/threat/TL-2026-0183) — critical — 2026-03-06
- [Seedworm (MuddyWater) Iranian MOIS APT Campaign Targeting U.S. Critical Infrastructure with Dindoor and…](https://intel.threadlinqs.com/threat/TL-2026-0176) — critical — 2026-03-06

## Related CVEs

CVEs referenced by the tracked threats that use T1561, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-8007](https://intel.threadlinqs.com/cve/CVE-2018-8007)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2023-29059](https://intel.threadlinqs.com/cve/CVE-2023-29059)
- [CVE-2024-1781](https://intel.threadlinqs.com/cve/CVE-2024-1781)
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971)
- [CVE-2025-2479](https://intel.threadlinqs.com/cve/CVE-2025-2479)
- [CVE-2025-24799](https://intel.threadlinqs.com/cve/CVE-2025-24799)
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-24294](https://intel.threadlinqs.com/cve/CVE-2026-24294)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-53483](https://intel.threadlinqs.com/cve/CVE-2026-53483)

## Detection coverage

Threadlinqs maintains 20 detection rules mapped to T1561 (SPL 7, KQL 5, Sigma 8). Rule content is available to Blue tier accounts and above; this page shows counts only.

20 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1561.001 Disk Content Wipe](https://intel.threadlinqs.com/technique/T1561.001) — 10 tracked threats
- T1561.002 Disk Structure Wipe — 3 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1561
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
