T1070.004 - File Deletion - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
March 31, 2026
Last Seen
July 22, 2026

T1070.004 - File Deletion is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.

T1070.004 - File Deletion is a mitre_attack tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed March 31, 2026; most recent activity July 22, 2026.

Related Threat Clusters

  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    699 articles · Updated April 29, 2026
  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026

Recent Intelligence Reports

  • APT34 (OilRig): Espionage on Your Infrastructure — Kelacyber · July 22, 2026
  • Salesloft Drift OAuth Token Breach Enables Salesforce Data Theft in UNC6395 'Icarus ... — Rescana · June 21, 2026
  • Hackers Insert Malware Into Mistral AI Software Download — Decrypt.Co · May 13, 2026
  • Axios Supply Chain Attack Deploys Cross-Platform RAT — Technadu · March 31, 2026
  • axios was compromised on npm with ~100 million weekly downloads — Reddit · March 31, 2026

Frequently asked questions

What is T1070.004 - File Deletion?

T1070.004 - File Deletion is a mitre_attack tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.

Is T1070.004 - File Deletion still active?

The most recent intelligence report mentioning T1070.004 - File Deletion on ThreatCluster is dated July 22, 2026. Activity was first observed March 31, 2026, giving a tracked span from then to July 22, 2026.

What is T1070.004 - File Deletion associated with?

Across ThreatCluster reporting, T1070.004 - File Deletion most frequently co-occurs with Apt33, Apt34, Apt39, Earth Simnavaz, Fox Kitten, among 12 tracked related entities.

What are the latest developments involving T1070.004 - File Deletion?

The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). T1070.004 - File Deletion appears across 3 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1070.004 - File Deletion?

T1070.004 - File Deletion appears in 5 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown