Activity timeline
T1686 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 14 reports, and 35 of the 35 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1686 Disable or Modify System Firewall is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 12 critical, 22 high, 1 medium.
Threats that use T1686 most often also use T1190 Exploit Public-Facing Application (22 threats), T1046 Network Service Discovery (17 threats), T1082 System Information Discovery (16 threats), T1685 Disable or Modify Tools (16 threats), T1005 Data from Local System (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
16 tracked threat actors appear in the threats that use T1686; the most frequent are DragonForce (3), Akira (1), BonJoviGoesHard (1), CUBA (1), ClickLock Dev (1).
Threat actors using it
Tracked threats
The 30 most recent of 35 tracked threats that use T1686.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Rootcritical
- CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCEcritical
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…critical
- Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAThigh
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)high
- CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEVcritical
- Pre-Auth Remote Code Execution in Enterprise Network Printer Firmware via Fuzzed Management Protocol (STAR…high
- Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)high
- ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…high
- UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaignhigh
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…critical
- Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003…medium
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)critical
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…high
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…high
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…critical
- CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)critical
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attackcritical
- DragonForce Ransomware Abuses Microsoft Teams TURN Relays to Hide Backdoor.Turn C2 Trafficcritical
- DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD…high
- Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)high
- Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…high
- Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruptionhigh
- OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relayhigh
- Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)high
- Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusionhigh
- Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy…high
Detection coverage
Threadlinqs maintains 42 detection rules mapped to T1686 (SPL 15, KQL 13, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1686.001 Cloud Firewall — 1 tracked threat
- T1686.002 Network Device Firewall — 0 tracked threats
- T1686.003 Windows Host Firewall — 0 tracked threats