One C2 kit. 30 customers. 2 governments

Summary

A cybersecurity analyst discovered that a state-linked intrusion set was using a command-and-control (C2) kit sourced from a commercial provider, shared with approximately 30 other customers, including two governments and numerous criminal operators. This indicates a trend where nation-state actors are renting infrastructure rather than building their own, complicating traditional attribution methods.

IFF Assessment

FOE

The use of shared C2 kits by both state-sponsored actors and cybercriminals blurs attribution lines and makes it harder for defenders to identify specific threat actors, presenting a challenge to defensive strategies.

Defender Context

Defenders need to be aware of the increasing trend of nation-state actors leveraging commercially available C2 kits. This convergence of state and criminal infrastructure means that traditional indicators of compromise (IOCs) may no longer be reliable for attributing attacks to specific actors, requiring a shift towards more sophisticated attribution techniques.

Read Full Story →