Tracking Threat Actors: How Infrastructure Analysis Reveals Cyber Attack Patterns
ID: ea3bca1e-e962-5ab1-b832-81a3a6e58c2b
STIX ID: report--ea3bca1e-e962-5ab1-b832-81a3a6e58c2b
Feed Name: Kudelski Security
Threat Score
This article outlines methodologies for mapping, clustering, and attributing adversary infrastructure using cross-referenced public and private data, illustrated by a CISA-phishing campaign attributed to Pioneer Kitten and a PuTTY-config leak tied to North Korean infrastructure; it covers IOC enrichment, historical DNS pivots, infrastructure tagging, the Diamond Model, and the challenges of inconsistent naming and long-term intelligence tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
