T1486Data Encrypted for Impact
T1486 — Data Encrypted for Impact is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 15 detection use cases covering it and 100 threat-intel articles citing it.
Impact
15Use cases
100Articles
0Sub-techniques
1Tactic
Use cases covering this technique (15)
Ransomware-style mass file rename / extension change ASL AWS Detect Users creating keys with encrypt policy without MFA AWS Detect Users creating keys with encrypt policy without MFA AWS Detect Users with KMS keys performing encryption S3 High Process Termination Frequency Ransomware Notes bulk creation Ryuk Test Files Detected Samsam Test File Write Windows .Key File Creation in Root Directory Windows BitLocker Suspicious Command Usage Windows DiskCryptor Usage [LLM] BitLocker tamper attempt via manage-bde or BitLocker PowerShell after WinRE shell access [LLM] Qilin Linux ransomware ELF payload (CVE-2026-50751 campaign) — known MD5 file event [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in tempArticles citing this technique (100)
high A tale of two eras art-40
crit CISA KEV: CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability art-111
crit Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection art-178
crit ESET Threat Report H2 2025 art-647
crit CISA KEV: CVE-2025-55182 — Meta React Server Components Remote Code Execution Vulnerability art-670
high In memoriam: David Harley art-713
crit CISA KEV: CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability art-844
crit CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability art-848
crit CISA KEV: CVE-2025-24472 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-956
crit CISA KEV: CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability art-998
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1032
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1051
crit CISA KEV: CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability art-1054
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1089
crit CISA KEV: CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability art-1115