# T1664 Exploitation for Initial Access

> As of 2026-10-10, T1664 (Exploitation for Initial Access) appears in 12 tracked threats, first reported 2026-07-03 and most recently 2026-10-10, with linked actors including NSO Group; it most often appears alongside T1404 (Exploitation for Privilege Escalation).

- **Tracked threats:** 12 (2 critical, 8 high, 1 medium)
- **First seen:** 2026-07-03
- **Last seen:** 2026-10-10
- **Threat actors:** 1
- **Detection rules:** 38 (counts only; Blue tier and above)

## Key facts

- **ID:** T1664
- **Framework:** MITRE ATT&CK
- **Tactics:** Initial Access (Mobile)
- **Matrix:** Mobile
- **Data as of:** 2026-10-10
- **MITRE:** https://attack.mitre.org/techniques/T1664/

## Activity timeline

T1664 first appeared in tracked threats on 2026-07-03 and was most recently reported on 2026-10-10. The busiest month was 2026-09 with 4 reports, and 12 of the 12 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1664 Exploitation for Initial Access is catalogued by MITRE ATT&CK under the Initial Access (Mobile) tactic in the Mobile matrix. Threadlinqs maps 12 of 2756 tracked threats (0.4%) to it; by severity that is 2 critical, 8 high, 1 medium.

Threats that use T1664 most often also use [T1404 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1404) (8 threats), [T1658 Exploitation for Client Execution](https://intel.threadlinqs.com/technique/T1658) (7 threats), [T1426 System Information Discovery](https://intel.threadlinqs.com/technique/T1426) (6 threats), [T1203 Exploitation for Client Execution](https://intel.threadlinqs.com/technique/T1203) (5 threats), [T1409 Stored Application Data](https://intel.threadlinqs.com/technique/T1409) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1664; the most frequent are [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) (1).

## Threat actors using it

- [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group) — 1

## Tracked threats

12 tracked threats use T1664.

- [Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level…](https://intel.threadlinqs.com/threat/TL-2026-3252) — high — 2026-10-10
- [Pwn2Own Ireland 2026: Google Pixel 10 Exploit Chains Earn $560,000](https://intel.threadlinqs.com/threat/TL-2026-3103) — medium — 2026-10-09
- [Paragon Graphite mercenary spyware: CEO admits no kill switch or misuse visibility; Citizen Lab confirmed…](https://intel.threadlinqs.com/threat/TL-2026-3053) — high — 2026-10-08
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write…](https://intel.threadlinqs.com/threat/TL-2026-2418) — critical — 2026-09-09
- [Pegasus Spyware Used to Hack Phone of Former MEP Stelios Kouloglou, PEGA Committee Member](https://intel.threadlinqs.com/threat/TL-2026-2324) — high — 2026-09-04
- [Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and…](https://intel.threadlinqs.com/threat/TL-2026-2316) — high — 2026-09-03
- [Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…](https://intel.threadlinqs.com/threat/TL-2026-2223) — high — 2026-08-29
- [Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Access](https://intel.threadlinqs.com/threat/TL-2026-2049) — high — 2026-08-17
- [NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions…](https://intel.threadlinqs.com/threat/TL-2026-1748) — 2026-07-28
- [European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit…](https://intel.threadlinqs.com/threat/TL-2026-1099) — critical — 2026-07-03
- [Pegasus Spyware (PWNYOURHOME Zero-Click Chain) Used Against European Parliament PEGA Committee Member…](https://intel.threadlinqs.com/threat/TL-2026-1098) — high — 2026-07-03

## Related CVEs

CVEs referenced by the tracked threats that use T1664, most frequent first.

- [CVE-2016-4655](https://intel.threadlinqs.com/cve/CVE-2016-4655)
- [CVE-2016-4656](https://intel.threadlinqs.com/cve/CVE-2016-4656)
- [CVE-2016-4657](https://intel.threadlinqs.com/cve/CVE-2016-4657)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2024-43047](https://intel.threadlinqs.com/cve/CVE-2024-43047)
- [CVE-2024-50302](https://intel.threadlinqs.com/cve/CVE-2024-50302)
- [CVE-2024-53104](https://intel.threadlinqs.com/cve/CVE-2024-53104)
- [CVE-2024-53197](https://intel.threadlinqs.com/cve/CVE-2024-53197)
- [CVE-2025-31200](https://intel.threadlinqs.com/cve/CVE-2025-31200)
- [CVE-2025-31201](https://intel.threadlinqs.com/cve/CVE-2025-31201)
- [CVE-2025-31717](https://intel.threadlinqs.com/cve/CVE-2025-31717)
- [CVE-2025-31718](https://intel.threadlinqs.com/cve/CVE-2025-31718)
- [CVE-2025-36934](https://intel.threadlinqs.com/cve/CVE-2025-36934)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2025-54957](https://intel.threadlinqs.com/cve/CVE-2025-54957)
- [CVE-2026-0106](https://intel.threadlinqs.com/cve/CVE-2026-0106)
- [CVE-2026-86950](https://intel.threadlinqs.com/cve/CVE-2026-86950)

## Detection coverage

Threadlinqs maintains 38 detection rules mapped to T1664 (SPL 13, KQL 12, Sigma 13). Rule content is available to Blue tier accounts and above; this page shows counts only.

38 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1664
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
