**Rethinking Infrastructure Attribution in an Era of Shared Cyber Tools**
In the world of cybersecurity, traditional assumptions about tracing attacks are being turned on their head. A recent deep dive by a security researcher highlights a startling reality: the infrastructure used in sophisticated cyberattacks is no longer a reliable indicator of who is behind them. Instead, shared tools, rented services, and communal code are blurring the lines between criminal operations and state-sponsored campaigns—forcing security teams to fundamentally rethink their strategies.
—
### The Blurred Line Between State and Crimeware
The researcher’s investigation began while mapping a state-linked intrusion set’s command-and-control (C2) infrastructure. To their surprise, the malware resolved its C2 address by reading a public blockchain contract. Initially, this appeared to be a unique fingerprint tied to a specific actor. However, further analysis revealed a startling truth: the contract was part of a family of byte-identical contracts, all deployed by the same builder and used by roughly 30 different operator wallets.
What does this mean? Two of those wallets appeared to be state-aligned, while the other 28 looked like standard crimeware operations. The key takeaway: **infrastructure is no longer a reliable differentiator**. Instead of identifying a single actor, the tools used by state-sponsored groups, criminals, and everyone in between are increasingly shared, rented, or repurposed.
—
### What a Shared Kit Does to Your Indicators
When multiple actors—whether state-affiliated or independent criminals—use the same C2 kit, any technical fingerprint becomes an “anti-signal.” Instead of narrowing down the attacker, highly specific indicators of compromise (IoCs) end up grouping unrelated actors together.
This phenomenon inverts traditional attribution models. Once, unique tools were seen as strong identifiers. Now, they’re more likely to mask the true actor behind an attack. As the researcher notes, **state programs no longer build their own infrastructure from scratch—they rent it**, often sourcing tools from the same underground markets as common criminals.
—
### Convergence Across the Threat Landscape
This issue isn’t isolated. Researchers from Mandiant, Microsoft, Lumen, and CISA have all observed similar patterns:
– **Mandiant** found that China-nexus actors route operations through contractor-controlled relay networks, making infrastructure ownership nearly impossible to pin down.
– **Microsoft and Lumen** documented Turla, an FSB-linked group, leveraging other criminals’ botnets, raising questions about whether the relationship was transactional or coercive.
– **CISA and the FBI** have identified Iranian state-linked groups operating as access brokers, selling footholds to ransomware gangs while obscuring their origins.
The takeaway? Whether motivated by sanctions (Iran, North Korea), cost efficiency (China), or plausible deniability (Russia), **no one owns their infrastructure anymore**.
—
### Why This Breaks Your Triage (Not Just Your Attribution)
This shift has serious operational consequences. Many SOCs still rely on presumed actor identity to triage incidents:
– Commodity malware = low severity
– Suspected state activity = high severity
But when tools like Amadey or Cobalt Strike are shared across criminals and intelligence services alike, that approach becomes dangerously misleading. A “low-severity” Amadey infection could actually mask an FSB operation, while a “high-severity” alert might stem from a teenage hacker using off-the-shelf ransomware.
To adapt, security teams must:
1. **Detach severity from attribution**
2. **Focus on what the attacker is doing—not who they might be**
3. **Anchor alerts on durable technical constants, like event signatures or custom encryption constants**
4. **Communicate confidence levels honestly in reports**
—
### FAQ
**Q: Can you still use infrastructure to attribute attacks?**
A: Not reliably. Shared infrastructure, rented servers, and blockchain-based C2 mean that technical indicators rarely point to a single actor.
**Q: How can my SOC detect nation-state activity if tools look the same as crimeware?**
A: Shift focus to behavior, not origin. Look at what an intruder is doing—access, persistence, exfiltration—and prioritize observable actions over presumed affiliations.
**Q: Does this mean attribution is impossible?**
A: Not impossible—but it requires layered evidence. On-chain data, malware analysis, and network telemetry should all contribute to a low-confidence conclusion rather than a definitive claim.
**Q: Are blockchain-based C2 systems untraceable?**
A: They’re harder to trace than traditional C2, but not invisible. Researchers have identified patterns in contract deployment and wallet activity that can reveal common infrastructure.
—
### Conclusion
The era of assuming that infrastructure equals ownership is over. As shared tools, rented access, and communal code become the norm, cybersecurity professionals must abandon outdated attribution models and focus on what really matters: **what’s happening, not who might be behind it**. By anchoring triage on observable behavior and technical constants—and being honest about uncertainty—organizations can build more resilient defenses in a world where the line between criminal and state-sponsored attacker is fading fast.



