# T1665 Hide Infrastructure

> As of 2026-10-05, T1665 (Hide Infrastructure) appears in 12 tracked threats, first reported 2026-02-03 and most recently 2026-09-15, with linked actors including Earth Lusca, APT28, Black Basta; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 12 (3 critical, 6 high, 3 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-09-15
- **Threat actors:** 5
- **Detection rules:** 14 (counts only; Blue tier and above)

## Key facts

- **ID:** T1665
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1665/

## Activity timeline

T1665 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-09-15. The busiest month was 2026-06 with 3 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1665 Hide Infrastructure is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 3 critical, 6 high, 3 medium.

Threats that use T1665 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (9 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (6 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (6 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

5 tracked threat actors appear in the threats that use T1665; the most frequent are [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) (1), [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) (1), [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) (1).

## Data sources

Telemetry that can reveal T1665, per MITRE ATT&CK.

- Domain Name — Domain Registration
- Internet Scan — Response Content, Response Metadata
- Network Traffic — Network Traffic Content

## Threat actors using it

- [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta) — 1
- [Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1

## Tracked threats

12 tracked threats use T1665.

- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network…](https://intel.threadlinqs.com/threat/TL-2026-2527) — high — 2026-09-15
- [Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks](https://intel.threadlinqs.com/threat/TL-2026-2471) — high — 2026-09-12
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar…](https://intel.threadlinqs.com/threat/TL-2026-2033) — medium — 2026-08-16
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for…](https://intel.threadlinqs.com/threat/TL-2026-1838) — critical — 2026-08-03
- [June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and…](https://intel.threadlinqs.com/threat/TL-2026-1353) — medium — 2026-07-15
- [148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)](https://intel.threadlinqs.com/threat/TL-2026-1304) — high — 2026-07-14
- [Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown](https://intel.threadlinqs.com/threat/TL-2026-1015) — critical — 2026-06-30
- [FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) &…](https://intel.threadlinqs.com/threat/TL-2026-0884) — high — 2026-06-20
- [BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass…](https://intel.threadlinqs.com/threat/TL-2026-0828) — high — 2026-06-16
- [Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign…](https://intel.threadlinqs.com/threat/TL-2026-0575) — critical — 2026-05-24
- [IPIDEA Residential Proxy Botnet Disruption by Google](https://intel.threadlinqs.com/threat/TL-2026-0042) — high — 2026-02-03

## Related CVEs

CVEs referenced by the tracked threats that use T1665, most frequent first.

- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040)
- [CVE-2026-26980](https://intel.threadlinqs.com/cve/CVE-2026-26980)

## Detection coverage

Threadlinqs maintains 14 detection rules mapped to T1665 (SPL 6, KQL 4, Sigma 4). Rule content is available to Blue tier accounts and above; this page shows counts only.

14 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1665
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
