# T1686 Disable or Modify System Firewall

> As of 2026-10-05, T1686 (Disable or Modify System Firewall) appears in 35 tracked threats, first reported 2026-02-02 and most recently 2026-10-03, with linked actors including DragonForce, Akira, BonJoviGoesHard; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 35 (12 critical, 22 high, 1 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-03
- **Threat actors:** 16
- **Detection rules:** 42 (counts only; Blue tier and above)

## Key facts

- **ID:** T1686
- **Framework:** MITRE ATT&CK
- **Tactics:** Defense Impairment
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1686/

## Activity timeline

T1686 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 14 reports, and 35 of the 35 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1686 Disable or Modify System Firewall is catalogued by MITRE ATT&CK under the Defense Impairment tactic in the Enterprise matrix. Threadlinqs maps 35 of 2623 tracked threats (1.3%) to it; by severity that is 12 critical, 22 high, 1 medium.

Threats that use T1686 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (22 threats), [T1046 Network Service Discovery](https://intel.threadlinqs.com/technique/T1046) (17 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (16 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (16 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (15 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

16 tracked threat actors appear in the threats that use T1686; the most frequent are [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) (3), [Akira](https://intel.threadlinqs.com/actor/Akira) (1), [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) (1), [CUBA](https://intel.threadlinqs.com/actor/CUBA) (1), [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) (1).

## Threat actors using it

- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 3
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 1
- [CUBA](https://intel.threadlinqs.com/actor/CUBA) — 1
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 1
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 1
- [INC Ransom - G1032](https://intel.threadlinqs.com/actor/INC%20Ransom%20-%20G1032) — 1
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 1
- [Lynx](https://intel.threadlinqs.com/actor/Lynx) — 1
- [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar) — 1
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 1
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 1

## Tracked threats

The 30 most recent of 35 tracked threats that use T1686.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — critical — 2026-09-18
- [CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE](https://intel.threadlinqs.com/threat/TL-2026-2440) — critical — 2026-09-10
- [CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by…](https://intel.threadlinqs.com/threat/TL-2026-2097) — critical — 2026-08-21
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)](https://intel.threadlinqs.com/threat/TL-2026-1837) — high — 2026-08-03
- [CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1650) — critical — 2026-07-23
- [Pre-Auth Remote Code Execution in Enterprise Network Printer Firmware via Fuzzed Management Protocol (STAR…](https://intel.threadlinqs.com/threat/TL-2026-1542) — high — 2026-07-19
- [Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)](https://intel.threadlinqs.com/threat/TL-2026-1521) — high — 2026-07-19
- [ClickLock Stealer: macOS ClickFix Infostealer Uses 210ms Process-Kill Loops and Fake Authentication Dialogs…](https://intel.threadlinqs.com/threat/TL-2026-1440) — high — 2026-07-17
- [UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign](https://intel.threadlinqs.com/threat/TL-2026-1413) — high — 2026-07-16
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…](https://intel.threadlinqs.com/threat/TL-2026-1390) — critical — 2026-07-15
- [Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003…](https://intel.threadlinqs.com/threat/TL-2026-1370) — medium — 2026-07-15
- [OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)](https://intel.threadlinqs.com/threat/TL-2026-1363) — critical — 2026-07-15
- [The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…](https://intel.threadlinqs.com/threat/TL-2026-1332) — high — 2026-07-14
- [Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint…](https://intel.threadlinqs.com/threat/TL-2026-1277) — high — 2026-07-13
- [GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…](https://intel.threadlinqs.com/threat/TL-2026-1271) — high — 2026-07-13
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644…](https://intel.threadlinqs.com/threat/TL-2026-1232) — critical — 2026-07-11
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — critical — 2026-07-10
- [JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack](https://intel.threadlinqs.com/threat/TL-2026-1117) — critical — 2026-07-05
- [DragonForce Ransomware Abuses Microsoft Teams TURN Relays to Hide Backdoor.Turn C2 Traffic](https://intel.threadlinqs.com/threat/TL-2026-2181) — critical — 2026-06-16
- [DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD…](https://intel.threadlinqs.com/threat/TL-2026-0819) — high — 2026-06-16
- [Exposed RDP / RDWeb Misconfigurations Exploited for Initial Access and Lateral Movement (Huntress 2026)](https://intel.threadlinqs.com/threat/TL-2026-0775) — high — 2026-06-11
- [Cloud Atlas APT — termsrv.dll Byte-Patch for Multi-Session RDP, PowerCloud/PowerShower/VBCloud Chain…](https://intel.threadlinqs.com/threat/TL-2026-0583) — high — 2026-05-25
- [Fragnesia — DirtyFrag-Family Linux Kernel LPE via XFRM ESP-in-TCP Page-Cache Corruption](https://intel.threadlinqs.com/threat/TL-2026-0510) — high — 2026-05-13
- [OpenClaw Hologram Rust Infostealer — Multi-Wave Campaign Abusing Hookdeck Webhook Gateway as C2 Relay](https://intel.threadlinqs.com/threat/TL-2026-0480) — high — 2026-05-07
- [Bissa Scanner — AI-Assisted Mass Exploitation and Credential Harvesting Campaign (@BonJoviGoesHard / Dr. Tube)](https://intel.threadlinqs.com/threat/TL-2026-0411) — high — 2026-04-22
- [Malicious Go crypto Module — Rekoobe Linux Backdoor via golang.org/x/crypto Namespace Confusion](https://intel.threadlinqs.com/threat/TL-2026-0164) — high — 2026-03-02
- [Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy…](https://intel.threadlinqs.com/threat/TL-2026-1468) — high — 2026-02-25

## Related CVEs

CVEs referenced by the tracked threats that use T1686, most frequent first.

- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-12356](https://intel.threadlinqs.com/cve/CVE-2024-12356)
- [CVE-2024-12686](https://intel.threadlinqs.com/cve/CVE-2024-12686)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-1094](https://intel.threadlinqs.com/cve/CVE-2025-1094)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)

## Detection coverage

Threadlinqs maintains 42 detection rules mapped to T1686 (SPL 15, KQL 13, Sigma 14). Rule content is available to Blue tier accounts and above; this page shows counts only.

42 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1686.001 Cloud Firewall — 1 tracked threat
- T1686.002 Network Device Firewall — 0 tracked threats
- T1686.003 Windows Host Firewall — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1686
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
