Activity timeline
T1685.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 32 of the 32 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1685.006 Clear Linux or Mac System Logs is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix, as a sub-technique of T1685 Disable or Modify Tools. Threadlinqs maps 32 of 2623 tracked threats (1.2%) to it; by severity that is 21 critical, 9 high, 2 medium.
Threats that use T1685.006 most often also use T1190 Exploit Public-Facing Application (26 threats), T1059.004 Unix Shell (23 threats), T1068 Exploitation for Privilege Escalation (22 threats), T1071.001 Web Protocols (19 threats), T1005 Data from Local System (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1685.006; the most frequent are UAT-8616 (3), UAT-9686 (2), VECT (2), Velvet Ant (2), INC Ransom (1).
Threat actors using it
Tracked threats
The 30 most recent of 32 tracked threats that use T1685.006.
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and…critical
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…high
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…high
- PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerabilityhigh
- VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KBhigh
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection…critical
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandemcritical
- SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Dayscritical
- Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink…high
- VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and…medium
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide…medium
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistencecritical
- Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)critical
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command…high
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited…critical
- Cisco Secure Workload CVE-2026-20223 — Maximum-Severity Unauthenticated Site Admin Privilege Escalation via…critical
- Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973…high
- PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…critical
- Quasar Linux (QLNX) — Sophisticated Linux RAT With LD_PRELOAD Rootkit, PAM Backdoor & DevOps Credential…high
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEVcritical
- VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data…critical
- CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitationcritical
- RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert…critical
- Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication…critical
- VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004…critical
- BPFDoor — Chinese Nation-State Linux Backdoor Using Berkeley Packet Filters for Covert C2 Activationcritical
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1685.006 (SPL 9, KQL 15, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1685 Disable or Modify Tools — 750 tracked threats at the technique level.