Activity timeline
T1685 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 268 reports, and 749 of the 750 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1685 Disable or Modify Tools is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 750 of 2623 tracked threats (28.6%) to it; by severity that is 223 critical, 451 high, 70 medium, 3 low.
Threats that use T1685 most often also use T1082 System Information Discovery (406 threats), T1027 Obfuscated Files or Information (382 threats), T1005 Data from Local System (365 threats), T1059 Command and Scripting Interpreter (363 threats), T1190 Exploit Public-Facing Application (298 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
158 tracked threat actors appear in the threats that use T1685; the most frequent are APT38 (19), Stardust Chollima (15), Sapphire Sleet (14), Lazarus Group (10), The Gentlemen (10).
Threat actors using it
Tracked threats
The 30 most recent of 750 tracked threats that use T1685.
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…medium
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scanshigh
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormhigh
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows…high
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and…high
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)high
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…critical
- BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustionmedium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)medium
- Larva-25012 Resumes Proxyware Distribution Campaign via DPLoader-Infected Systemsmedium
Detection coverage
Threadlinqs maintains 653 detection rules mapped to T1685 (SPL 210, KQL 224, Sigma 219). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1685.001 Disable or Modify Windows Event Log — 9 tracked threats
- T1685.002 Disable or Modify Cloud Log — 11 tracked threats
- T1685.003 Modify or Spoof Tool UI — 0 tracked threats
- T1685.004 Disable or Modify Linux Audit System Log — 0 tracked threats
- T1685.005 Clear Windows Event Logs — 41 tracked threats
- T1685.006 Clear Linux or Mac System Logs — 32 tracked threats