WALKING IN YOUR ENEMY’S SHADOW: WHEN FOURTH-PARTY COLLECTION BECOMES ATTRIBUTION HELL
2017-08-30 • Kaspersky •
Attachments
Guerrero-Saade and Raiu examine how fourth-party collection complicates cyber-espionage attribution when one intelligence or threat actor compromises another and reuses its access, tools, or infrastructure. The excerpt describes attacker-on-attacker operations, proprietary toolkit reuse, exploit repurposing, and C2 infrastructure piggybacking as situations that can make activity clusters appear to belong to the wrong actor. It argues that public reporting and expected TTP profiles can themselves be manipulated, with actors adopting another group’s tradecraft to blend into established attribution narratives. The material is relevant for CTI workflows because it cautions analysts to separate observed evidence from actor labels, especially when overlaps may reflect tool theft, shared victims, or compromised infrastructure rather than a single operator.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | flashserv.net | 2017-08-30 | 2018-09-06 |
| DOMAIN | update.craftx.biz | 2017-08-30 | 2018-09-06 |
| DOMAIN | download.ns360.info | 2017-08-30 | 2018-09-06 |
| DOMAIN | checkupdates.flashserv.net | 2017-08-30 | 2018-09-06 |
| HASH | 58a4d93d386736cb9843a267c7c3c10b | 2017-08-30 | 2017-08-30 |
| HASH | 99a18bf3c04a491b256f7d60eb6e0f26 | 2017-08-30 | 2017-08-30 |
| HASH | 6355c82c7c6a90ef41824a03bbabbabc | 2017-08-30 | 2017-08-30 |
| URL | http://www.chateau-eu.fr/wp-con… | 2017-08-30 | 2017-08-30 |
| URL | https://edwardsnowden.com/wp-co… | 2017-08-30 | 2017-08-30 |
| URL | http://www.chateau-eu.fr/wp-con… | 2017-08-30 | 2017-08-30 |
| URL | http://scarcroft.net/wp-content… | 2017-08-30 | 2017-08-30 |
| URL | http://www.chateau-eu.fr/wp-con… | 2017-08-30 | 2017-08-30 |
| URL | http://www.volatilityfoundation… | 2017-08-30 | 2017-08-30 |
| URL | http://www.chateau-eu.fr/wp-con… | 2017-08-30 | 2017-08-30 |
| URL | http://scarcroft.net/plus/thumb… | 2017-08-30 | 2017-08-30 |
| DOMAIN | fes-caucasus.org | 2017-08-30 | 2017-08-30 |
| DOMAIN | cafe.daum.net | 2017-08-30 | 2017-08-30 |
| DOMAIN | download1.ns360.info | 2017-08-30 | 2017-08-30 |
| DOMAIN | scarcroft.net | 2017-08-30 | 2017-08-30 |
| DOMAIN | rfchosun.org | 2017-08-30 | 2017-08-30 |
| DOMAIN | mozilla.tftpd.net | 2017-08-30 | 2017-08-30 |
| IPv4 | 84.45.76.100 | 2017-08-30 | 2017-08-30 |
| IPv4 | 54.251.107.25 | 2017-08-30 | 2017-08-30 |
| IPv4 | 89.46.102.43 | 2017-08-30 | 2017-08-30 |
| IPv4 | 29.214.39.124 | 2017-08-30 | 2017-08-30 |