How Can Attackers Manipulate Cyber Attribution?

303 views
β€’
May 17, 2019
by
RSAC Cybersecurity
YouTube video player
How Can Attackers Manipulate Cyber Attribution?

TL;DR

Cyber attribution can be deliberately manipulated because analysts often connect incidents through shared tools, tactics, infrastructure, and code metadata that attackers may copy or fabricate. Security teams should treat attribution as potentially deceptive and focus decisions on the outcomes attackers seek, since a deception can succeed strategically even when investigators uncover it later.

Transcript

So today we're gonna be talking about deception and how it applies to the world of cyber intelligence analysis. So between us, uh, John and I have about a, a couple of decades of experience in looking at cyber threats and trying to attribute them. It's part of what we do as intelligence analysts. That's, that's both of our backgrounds, is in siftin... Read More

Key Insights

  • Cyber attribution consists of both grouping related incidents and identifying the responsible culprit. Grouping establishes that multiple intrusions likely share an operator, while culprit identification attempts to connect that activity to a criminal, nation state, organization, or another responsible entity.
  • Shared tools are useful but fallible attribution signals because the same malware can appear across multiple incidents. Attackers may reuse publicly available tools or adopt malware already associated with another operator, creating apparent connections that do not necessarily reflect common control.
  • Shared tactics, techniques, and procedures can connect activity when operators repeatedly behave in recognizable ways. An example is using the same email address for spear-phishing lures, but published descriptions of such behavior can also teach adversaries which characteristics investigators use to form links.
  • Code metadata can preserve characteristics of the environment used to build malware. PDB strings and rich headers may help investigators compare samples, yet attackers with forethought and patience can configure development environments or alter artifacts so the resulting code presents selected characteristics.
  • Olympic Destroyer demonstrates deliberate manipulation of malware metadata. The operation copied rich headers from malware previously associated with the so-called Lazarus Group, which the presenters and other organizations believed was linked to North Korean sponsorship, then inserted those headers into different code.
  • Public attribution research strengthens defense by explaining connections among incidents and exposing attacker behavior. The same publications also reveal investigative methods to adversaries, allowing them to identify which tools, metadata, infrastructure, and operational patterns could be reproduced to misdirect future analysis.
  • The purpose of deception is to create an advantageous outcome, not to maintain a false account forever. A deceptive operation may achieve its objective before an investigation reveals the manipulation, making delayed correction insufficient to reverse the strategic result.
  • Security decisions should account for uncertainty created by deliberate deception. Analysts, security operations personnel, threat researchers, and business leaders need to consider whether observed attribution signals arose naturally, were copied through ordinary tool reuse, or were intentionally planted to influence conclusions.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is cyber threat attribution analysis?

Cyber threat attribution analysis involves two distinct activities. The first groups intrusions or incidents that appear tied to a common operator, often through shared malware or tactics. The second tries to identify the actual culprit, such as a criminal, nation state, or organization, using evidence that may include infrastructure ownership, malware strings, code metadata, and online identities.

Q: How can attackers manipulate cyber attribution?

Attackers can manipulate attribution by studying the evidence researchers publicly use and then reproducing or altering those signals. They may reuse another operator's tools, imitate tactics, manipulate PDB strings or rich headers, establish misleading infrastructure, or insert identity clues. These actions can make unrelated operations appear connected or encourage investigators to identify the wrong culprit.

Q: Why are shared malware tools weak attribution evidence?

Shared malware tools can connect incidents, but they do not prove that one operator controlled every incident. Many tools are publicly available, and attackers can obtain and reuse software previously associated with another group. Cobalt Strike Beacon is presented as an example frequently encountered in incident response, illustrating how widespread tool reuse can complicate conclusions about common ownership.

Q: How can malware code metadata mislead investigators?

Malware code metadata can reflect characteristics of the development environment used to compile a program. Investigators may compare PDB strings, rich headers, and related build artifacts across samples. An attacker can create a virtual machine and development environment designed to leave chosen impressions, or directly copy selected metadata, causing the malware to resemble another operator's work.

Q: What does Olympic Destroyer show about misattribution?

Olympic Destroyer shows that an attacker can deliberately copy technical characteristics associated with another threat group. The operator took rich headers from malware previously linked to the so-called Lazarus Group and inserted an exact copy into its own code. The example demonstrates that apparently precise build metadata may be planted rather than naturally produced by development activity.

Q: Why does exposing a deception not necessarily defeat it?

Exposing a deception later does not necessarily reverse the outcome it enabled. The 1931 Manchurian example shows Japan using a largely ineffective railway explosion as justification to attack Chinese military installations and consolidate regional control. By the time the League of Nations assigned blame to Japan in 1932, the desired territorial outcome had already been achieved.

Q: How does public threat research help attackers deceive analysts?

Public threat research is essential for defenders because it documents malicious tools, behaviors, and connections among incidents. However, publication also shows attackers which signals analysts rely upon. An adversary can examine reports describing shared malware, tactics, infrastructure, or metadata, then reproduce those characteristics to create false links and steer investigators toward a selected attribution conclusion.

Q: How should security teams handle uncertain attribution?

Security teams should treat attribution as an analytical judgment that may be affected by deliberate manipulation. Analysts should consider whether each signal is difficult to fabricate, whether common tool reuse offers a simpler explanation, and whether several independent evidence types support the same conclusion. Risk decisions should also address attacker behavior and desired outcomes rather than depending entirely on identity.

Summary & Key Takeaways

  • Cyber attribution analysis performs two related tasks: grouping incidents under a common operator and identifying the responsible culprit. Analysts connect activity using evidence such as shared malware, tactics, email addresses, infrastructure ownership, code characteristics, and identities found on criminal forums. Each signal can contribute useful information, but it may also be manipulated.

  • Attackers can study publicly released attribution research and reverse engineer the techniques investigators use. Reusing public tools is relatively easy, while deliberately modifying build artifacts such as PDB strings and rich headers requires more planning. Even so, sophisticated operators can construct development environments that leave misleading characteristics in compiled malware.

  • Deception is valuable when it creates a favorable outcome for the deceiver, even if investigators later expose the false story. Security teams should therefore account for possible manipulation when assessing attribution and making risk decisions. The central challenge is distinguishing genuinely shared operational behavior from evidence planted to imitate another actor.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š