Attribution and its limits
Attribution is the fastest way to fail a scenario interview. The skill is not naming the actor — it is knowing what your evidence can and cannot support, and saying so.
Almost every scenario round contains a moment where naming an actor is tempting. How you handle that moment is often the whole assessment. The correct instinct is not refusal — it is proportionality.
Three different claims
These get collapsed into the word "attribution", and separating them is most of the skill:
- Clustering. "These intrusions share enough tradecraft, tooling and infrastructure that they are likely the same operator." This is a technical judgement you can often support well.
- Naming. "This cluster corresponds to what vendor X calls Group Y." This is a mapping exercise between your cluster and someone else's, and it is far shakier than it looks.
- Sponsorship. "This group operates on behalf of a particular state or organisation." This usually depends on intelligence a private-sector analyst does not have, and should be reported as someone else's claim rather than your own finding.
"I would cluster this activity and track it under our own designation. I would note the overlap with publicly reported Group Y as an observation with the specific evidence, at moderate confidence, and I would not assert sponsorship at all. Here is what would move me."
Why vendor names do not line up
Different vendors see different slices of the same activity, cluster on different criteria, and publish on different timelines. The result is that two names for "the same" group almost never cover exactly the same set of activity — one may include operations the other excludes, or split what another treats as one actor.
Practical consequences: never treat an equivalence table as authoritative; always say which reporting your mapping is based on; and prefer your own internal cluster designation as the thing you actually track. Naming conventions themselves vary by vendor (numbered sets, themed animal or weather names, and so on) and carry no shared meaning about capability or sponsorship.
What the evidence is worth
| Evidence | Attribution weight | Why |
|---|---|---|
| Shared C2 IP or VPS | Low | Shared hosting, resold infrastructure, compromised third parties |
| Shared domain registration pattern | Low–moderate | Useful for clustering; trivially changed |
| Commodity malware family | Very low | Sold, leaked or shared across unrelated actors |
| Custom tooling with code overlap | Moderate–high | Expensive to develop; but builders leak |
| Distinctive tradecraft sequence | Moderate–high | Habits are hard to change; near the top of the Pyramid of Pain |
| Victimology consistent with a known intent | Moderate | Strong corroborator, weak on its own |
| Operational security mistakes | Situational | Occasionally decisive; also the classic false-flag vector |
| Language, timezone, build artefacts | Low | Easily faked, and routinely faked deliberately |
False flags are real
The Olympic Destroyer malware deployed against the 2018 Winter Olympics is the standard case study, and it is worth knowing properly. It carried planted artefacts — including code characteristics resembling a different, known actor — apparently intended to mislead analysts who relied on tooling similarity. Several early public assessments pointed in directions that later analysis did not support.
The lesson is not "attribution is impossible". It is that the artefacts easiest to observe are also the easiest to plant, and that an assessment resting on a single class of evidence is fragile. Weight your judgement toward things the adversary would find expensive to fake, and state which class of evidence you are leaning on.
Bias to guard against
- Cui bono as a shortcut. "Who benefits" generates hypotheses. It does not confirm them, and it is the door through which political assumptions enter technical analysis.
- Anchoring on the first plausible name. Once a group name is in the room it distorts everything after it. This is exactly what ACH exists to counter.
- Circular reporting. Four articles citing one original source is one source. See source grading.
- Stakeholder pressure. Someone senior will want a name for a board slide. The professional answer is to give them the decision-relevant assessment and be explicit about what is not supported.
Does attribution even matter?
A good interview follow-up, and the honest answer is "it depends on the decision". For patching, segmentation and detection engineering, TTPs matter and the name adds nothing. For legal action, insurance, sanctions exposure, or predicting what the adversary does next against you, identity and intent genuinely change the response. Say which case you are in.
Express all of this with calibrated confidence language. Practise attribution questions.
Run a mock interview on this material. You get the question, a graded response against a vetted rubric, and the probing follow-up an interviewer would ask next.
Related reading
- Analytic confidence and estimative language These are two different axes. You can be highly confident that something is unlikely. If you cannot say that sentence and explain it, you will lose points in every scenario round.
- Source grading for analysts A reliable source can report something false. An unreliable source can be right. Grading them on one axis loses the information that matters.
- Structured analytic techniques ACH is not a spreadsheet ritual. It is a discipline for finding the evidence that would prove you wrong, which is the only kind that carries much information.
- Writing intelligence reports You will be judged on your writing more than your tooling. The bar is a judgement up front, evidence behind it, and an explicit "so what" for someone you have named.