WALKING IN YOUR ENEMY’S SHADOW: WHEN FOURTH-PARTY COLLECTION BECOMES ATTRIBUTION HELL

2017-08-30 Kaspersky

https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07170728/Guerrero-Saade-Raiu-VB2017.pdf

Attachments

Guerrero-Saade-Raiu-VB2017.pdf (2 MB)

Thumbnail for WALKING IN YOUR ENEMY’S SHADOW: WHEN FOURTH-PARTY COLLECTION BECOMES ATTRIBUTION HELL

Guerrero-Saade and Raiu examine how fourth-party collection complicates cyber-espionage attribution when one intelligence or threat actor compromises another and reuses its access, tools, or infrastructure. The excerpt describes attacker-on-attacker operations, proprietary toolkit reuse, exploit repurposing, and C2 infrastructure piggybacking as situations that can make activity clusters appear to belong to the wrong actor. It argues that public reporting and expected TTP profiles can themselves be manipulated, with actors adopting another group’s tradecraft to blend into established attribution narratives. The material is relevant for CTI workflows because it cautions analysts to separate observed evidence from actor labels, especially when overlaps may reflect tool theft, shared victims, or compromised infrastructure rather than a single operator.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN flashserv.net 2017-08-30 2018-09-06
DOMAIN update.craftx.biz 2017-08-30 2018-09-06
DOMAIN download.ns360.info 2017-08-30 2018-09-06
DOMAIN checkupdates.flashserv.net 2017-08-30 2018-09-06
HASH 58a4d93d386736cb9843a267c7c3c10b 2017-08-30 2017-08-30
HASH 99a18bf3c04a491b256f7d60eb6e0f26 2017-08-30 2017-08-30
HASH 6355c82c7c6a90ef41824a03bbabbabc 2017-08-30 2017-08-30
URL http://www.chateau-eu.fr/wp-con… 2017-08-30 2017-08-30
URL https://edwardsnowden.com/wp-co… 2017-08-30 2017-08-30
URL http://www.chateau-eu.fr/wp-con… 2017-08-30 2017-08-30
URL http://scarcroft.net/wp-content… 2017-08-30 2017-08-30
URL http://www.chateau-eu.fr/wp-con… 2017-08-30 2017-08-30
URL http://www.volatilityfoundation… 2017-08-30 2017-08-30
URL http://www.chateau-eu.fr/wp-con… 2017-08-30 2017-08-30
URL http://scarcroft.net/plus/thumb… 2017-08-30 2017-08-30
DOMAIN fes-caucasus.org 2017-08-30 2017-08-30
DOMAIN cafe.daum.net 2017-08-30 2017-08-30
DOMAIN download1.ns360.info 2017-08-30 2017-08-30
DOMAIN scarcroft.net 2017-08-30 2017-08-30
DOMAIN rfchosun.org 2017-08-30 2017-08-30
DOMAIN mozilla.tftpd.net 2017-08-30 2017-08-30
IPv4 84.45.76.100 2017-08-30 2017-08-30
IPv4 54.251.107.25 2017-08-30 2017-08-30
IPv4 89.46.102.43 2017-08-30 2017-08-30
IPv4 29.214.39.124 2017-08-30 2017-08-30

Related Actors

Related Reports

« Back