Tracking Threat Actors: How Infrastructure Analysis Reveals Cyber Attack Patterns

2025-03-05 Kudelski Security

https://research.kudelskisecurity.com/2025/03/05/tracking-threat-actors-how-infrastructure-analysis-reveals-cyber-attack-patterns/

Thumbnail for Tracking Threat Actors: How Infrastructure Analysis Reveals Cyber Attack Patterns

Kudelski Security uses infrastructure analysis to show how analysts can cluster and revisit adversary networks over time, with a DPRK-relevant case study based on leaked North Korean IT worker PuTTY configuration data. The reconstructed infrastructure is assessed as possibly part of a wider network, potentially linked to Kaesong and ZTE references, although the article stresses that the purpose and exact North Korea relationship remain uncertain. The report recommends tagging uncertain infrastructure with explicit confidence levels, preserving historical DNS and telemetry pivots, and updating clusters as new overlaps appear. It also uses Lazarus as an example of how activity matrices can organize operators, operations, and infrastructure while warning that vendor naming conventions and attribution boundaries differ across intelligence sources.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://gopivot.ing/map/ 2025-03-05 2025-03-05
URL https://gopivot.ing/ 2025-03-05 2025-03-05
DOMAIN hopers.ru 2025-03-05 2025-03-05
DOMAIN gopivot.ing 2025-03-05 2025-03-05
IPv4 206.71.148.78 2025-03-05 2025-03-05
URL https://cyb3rops.medium.com/the… 2024-10-08 2025-03-05
DOMAIN cyb3rops.medium.com 2024-10-08 2025-03-05

Related Reports

« Back