T1490 - Inhibit System Recovery is a mitre_attack tracked by ThreatCluster, appearing in 18 threat clusters built from 20 intelligence report mentions.
T1490 - Inhibit System Recovery is a mitre_attack tracked across 18 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 18, 2026.
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
A critical vulnerability in the Nginx-UI backup restore mechanism, identified as CVE-2026-33026, has been disclosed. This flaw enables attackers to manipulate encrypted backup archives, potentially injecting malicious…
Payload ransomware, first identified in February 2026, has rapidly expanded its operations, targeting logistics, real estate, and manufacturing sectors worldwide. The malware employs ChaCha20 encryption and Curve25519…
In March 2026, the Trigona ransomware group, which operates as a Ransomware-as-a-Service (RaaS), utilized a newly developed custom tool named 'uploader_client.exe' to enhance their data exfiltration capabilities. This…
The Kyber ransomware group has launched a coordinated attack targeting both Windows file servers and VMware ESXi systems. In March 2026, cybersecurity firm Rapid7 analyzed two variants of the ransomware deployed in the…
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
The hacking group Cyber Isnaad Front announced the destruction of 120 terabytes of sensitive financial and defense data after breaching several Israeli firms. The operation targeted key organizations, including Oren…
Kaspersky's research reveals that The Gentlemen ransomware group, active since mid-2025, is expanding its operations with new custom-built malware tools. This group targets various industries, including healthcare and…
T1490 - Inhibit System Recovery is a mitre_attack tracked by ThreatCluster, appearing in 18 threat clusters built from 20 intelligence report mentions.
The most recent intelligence report mentioning T1490 - Inhibit System Recovery on ThreatCluster is dated July 18, 2026. Activity was first observed November 6, 2025, giving a tracked span from then to July 18, 2026.
Across ThreatCluster reporting, T1490 - Inhibit System Recovery most frequently co-occurs with Bronze Butler, Tick, Brute Force, Credential Stuffing, Data Breach, among 12 tracked related entities.
The most significant recent cluster is “Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions” (8 articles · Updated April 21, 2026). T1490 - Inhibit System Recovery appears across 18 threat clusters in total, listed above with sources.
T1490 - Inhibit System Recovery appears in 20 intelligence report mentions across 18 deduplicated threat clusters, aggregated from 17,000+ monitored sources.