Activity timeline
T1665 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 3 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1665 Hide Infrastructure is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 6 high, 3 medium.
Threats that use T1665 most often also use T1027 Obfuscated Files or Information (9 threats), T1082 System Information Discovery (6 threats), T1140 Deobfuscate/Decode Files or Information (6 threats), T1190 Exploit Public-Facing Application (6 threats), T1036 Masquerading (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
5 tracked threat actors appear in the threats that use T1665; the most frequent are Earth Lusca (2), APT28 (1), Black Basta (1), Sable Squirrel (1), Sandworm (1).
Data sources
Telemetry that can reveal T1665, per MITRE ATT&CK.
- Domain Name — Domain Registration
- Internet Scan — Response Content, Response Metadata
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
12 tracked threats use T1665.
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…high
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networkshigh
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar…medium
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…critical
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…medium
- 148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)high
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdowncritical
- FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…high
- BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass…high
- Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…critical
- IPIDEA Residential Proxy Botnet Disruption by Googlehigh
Detection coverage
Threadlinqs maintains 14 detection rules mapped to T1665 (SPL 6, KQL 4, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.