ctianalyst.com

Attribution and its limits

Attribution is the fastest way to fail a scenario interview. The skill is not naming the actor — it is knowing what your evidence can and cannot support, and saying so.

Almost every scenario round contains a moment where naming an actor is tempting. How you handle that moment is often the whole assessment. The correct instinct is not refusal — it is proportionality.

Three different claims

These get collapsed into the word "attribution", and separating them is most of the skill:

  1. Clustering. "These intrusions share enough tradecraft, tooling and infrastructure that they are likely the same operator." This is a technical judgement you can often support well.
  2. Naming. "This cluster corresponds to what vendor X calls Group Y." This is a mapping exercise between your cluster and someone else's, and it is far shakier than it looks.
  3. Sponsorship. "This group operates on behalf of a particular state or organisation." This usually depends on intelligence a private-sector analyst does not have, and should be reported as someone else's claim rather than your own finding.
The answer that scores

"I would cluster this activity and track it under our own designation. I would note the overlap with publicly reported Group Y as an observation with the specific evidence, at moderate confidence, and I would not assert sponsorship at all. Here is what would move me."

Why vendor names do not line up

Different vendors see different slices of the same activity, cluster on different criteria, and publish on different timelines. The result is that two names for "the same" group almost never cover exactly the same set of activity — one may include operations the other excludes, or split what another treats as one actor.

Practical consequences: never treat an equivalence table as authoritative; always say which reporting your mapping is based on; and prefer your own internal cluster designation as the thing you actually track. Naming conventions themselves vary by vendor (numbered sets, themed animal or weather names, and so on) and carry no shared meaning about capability or sponsorship.

What the evidence is worth

EvidenceAttribution weightWhy
Shared C2 IP or VPSLowShared hosting, resold infrastructure, compromised third parties
Shared domain registration patternLow–moderateUseful for clustering; trivially changed
Commodity malware familyVery lowSold, leaked or shared across unrelated actors
Custom tooling with code overlapModerate–highExpensive to develop; but builders leak
Distinctive tradecraft sequenceModerate–highHabits are hard to change; near the top of the Pyramid of Pain
Victimology consistent with a known intentModerateStrong corroborator, weak on its own
Operational security mistakesSituationalOccasionally decisive; also the classic false-flag vector
Language, timezone, build artefactsLowEasily faked, and routinely faked deliberately

False flags are real

The Olympic Destroyer malware deployed against the 2018 Winter Olympics is the standard case study, and it is worth knowing properly. It carried planted artefacts — including code characteristics resembling a different, known actor — apparently intended to mislead analysts who relied on tooling similarity. Several early public assessments pointed in directions that later analysis did not support.

The lesson is not "attribution is impossible". It is that the artefacts easiest to observe are also the easiest to plant, and that an assessment resting on a single class of evidence is fragile. Weight your judgement toward things the adversary would find expensive to fake, and state which class of evidence you are leaning on.

Bias to guard against

  • Cui bono as a shortcut. "Who benefits" generates hypotheses. It does not confirm them, and it is the door through which political assumptions enter technical analysis.
  • Anchoring on the first plausible name. Once a group name is in the room it distorts everything after it. This is exactly what ACH exists to counter.
  • Circular reporting. Four articles citing one original source is one source. See source grading.
  • Stakeholder pressure. Someone senior will want a name for a board slide. The professional answer is to give them the decision-relevant assessment and be explicit about what is not supported.

Does attribution even matter?

A good interview follow-up, and the honest answer is "it depends on the decision". For patching, segmentation and detection engineering, TTPs matter and the name adds nothing. For legal action, insurance, sanctions exposure, or predicting what the adversary does next against you, identity and intent genuinely change the response. Say which case you are in.

Express all of this with calibrated confidence language. Practise attribution questions.

Next step

Run a mock interview on this material. You get the question, a graded response against a vetted rubric, and the probing follow-up an interviewer would ask next.

Related reading