# T1685.002 Disable or Modify Cloud Log

> As of 2026-10-05, T1685.002 (Disable or Modify Cloud Log) appears in 11 tracked threats, first reported 2026-02-16 and most recently 2026-07-22, with linked actors including EvilTokens, INC Ransom, INC Ransom - G1032; it most often appears alongside T1036.005 (Match Legitimate Resource Name or Location).

- **Tracked threats:** 11 (4 critical, 7 high)
- **First seen:** 2026-02-16
- **Last seen:** 2026-07-22
- **Threat actors:** 8
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1685.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Parent:** T1685
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1685/002/

## Activity timeline

T1685.002 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-07-22. The busiest month was 2026-07 with 8 reports, and 11 of the 11 threats were reported in the twelve months to 2026-07.

## How adversaries use it

T1685.002 Disable or Modify Cloud Log is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 4 critical, 7 high.

Threats that use T1685.002 most often also use [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (5 threats), [T1078.004 Cloud Accounts](https://intel.threadlinqs.com/technique/T1078.004) (5 threats), [T1087.004 Cloud Account](https://intel.threadlinqs.com/technique/T1087.004) (5 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (5 threats), [T1016 System Network Configuration Discovery](https://intel.threadlinqs.com/technique/T1016) (4 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1685.002; the most frequent are [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) (1), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) (1), [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) (1), [Lynx](https://intel.threadlinqs.com/actor/Lynx) (1), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (1).

## Threat actors using it

- [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 1
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 1
- [UNK_OutFlareAZ](https://intel.threadlinqs.com/actor/UNK_OutFlareAZ) — 1
- [UNK_pyreq2323](https://intel.threadlinqs.com/actor/UNK_pyreq2323) — 1

## Tracked threats

11 tracked threats use T1685.002.

- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1454) — high — 2026-07-17
- [OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 &…](https://intel.threadlinqs.com/threat/TL-2026-1342) — high — 2026-07-14
- [NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of…](https://intel.threadlinqs.com/threat/TL-2026-1279) — critical — 2026-07-13
- [GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…](https://intel.threadlinqs.com/threat/TL-2026-1271) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege…](https://intel.threadlinqs.com/threat/TL-2026-1060) — high — 2026-07-02
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens…](https://intel.threadlinqs.com/threat/TL-2026-1036) — high — 2026-07-01
- [Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…](https://intel.threadlinqs.com/threat/TL-2026-0548) — critical — 2026-05-21
- [Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration](https://intel.threadlinqs.com/threat/TL-2026-0529) — critical — 2026-05-19
- [CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…](https://intel.threadlinqs.com/threat/TL-2026-0112) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1685.002, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-55241](https://intel.threadlinqs.com/cve/CVE-2025-55241)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-62554](https://intel.threadlinqs.com/cve/CVE-2025-62554)
- [CVE-2025-62557](https://intel.threadlinqs.com/cve/CVE-2025-62557)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1685.002 (SPL 5, KQL 8, Sigma 5). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) — 750 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1685.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
