Tell us a bit about the Secureworks Counter Threat Unit (CTU)?
The Secureworks Counter Threat Unit™ (CTU) research team is made up of more than 75 researchers across the globe. The team analyses threat data across our global customer base and actively monitors the threat landscape. We deliver advanced, unique intelligence on the adversary and the current threat landscape.
We do this through research into trillions of events, more than a thousand annual incident response (IR) engagements across a diverse global customer base. That research is supported and enabled by over ten years investment in tooling and technology to scale and automate research playbooks.
The intelligence we gather is applied across our platforms and systems to improve detection and response efforts for our customers, threat context helps customers understand how to respond.
CTU is well engaged with the wider security community through Secureworks relationships: for example, in the UK we have been a member of the NCSC CIR scheme since its inception.
What are the key things you look for in those detection and response efforts?
When investigating any security incident, we are looking for the “what and how”, validating our existing customer protections and countermeasures, and also the “who and why” so we can understand the motivation for the attack in terms of money, data, or disruption, and the likely next actions in the adversary’s playbook.
To do this, we use structured decision-making models. One example is the diamond model of intrusion analysis, which is a standard industry model. This has four vertices: actor, tooling, infrastructure, victim. In practise, if we look at an attack and we can see common infrastructure and tooling being used to target a similar victim type – let’s say healthcare providers – then we can assert with some confidence that this cluster of activity is coming from the same actor.
But it is not a straightforward process. In the past state threat actors used bespoke malware so it was fairly easy to look at what had been deployed and attribute that to a specific group. But the intention of state actors is to be covert – if you are discovered you lose both operationally and politically. While having a bespoke tool may be useful, if it’s giving away who the adversary is, then it’s not fit for purpose. As a result, we now see them increasingly retooling, using malware that is widely available, making it harder to attribute any specific incident.
It is important that when we confirm an attribution, we are confident in our assessment.
Why is attribution of cyberattacks so important?
On an emotional level, attribution is important to the victim. Organisations want to know who has attacked them and why. For researchers, if we know “who” then we can focus on the “how”. Knowing an attacker’s full identity is not always necessary, but having a specific threat actor profile gives you a better understanding of your adversary’s tradecraft, behaviours, and motives. Nation states behave very differently to criminals. And the way we approach evicting them from an environment is also very different. Attribution helps triage and advise immediate containment strategies by knowing who you are dealing with.
A good threat actor profile also improves our ability to disrupt the attack and eradicate the adversary’s presence in the environment. If we can link observed tactics, tradecraft, or indicators to a known threat actor profile, we can respond to the threat in a more focussed fashion.
Again, attribution helps with eviction strategies. If you see ransomware precursors on your network, containment should be immediate as the risk of harm is upon your organisation. If you attribute to a hostile state actor then you may wish to monitor and understand the full envelope of exposure before eviction, very different.
Attribution is of course a complete minefield. Major cybersecurity vendors each have their own definitions and boundaries for different threat groups and actors. For Secureworks, it is critical that we maintain our own definitions, informed by first hand observations. To help the community, we keep a ‘Rosetta Stone’ of threat actors on our website which we are constantly updating.
How do you assign confidence levels to your attribution?
Confidence levels follow the definitions from the U.S. Director of National Intelligence and depend on the quality and quantity of corroborating data. When we make an attribution statement about cyber activity, we attach a confidence level to it. It shows the likelihood of an attribution being correct, although even a high confidence attribution isn’t guaranteed correct.
High confidence when making attributions is important for many reasons. Attributions can impact the broader political debate: for example, when the FBI points to hostile activity from China or Russia. It is essential for law enforcement activity.
There have been several examples of attacks where early judgements about who was responsible turned out to be mistaken. Sometimes that can be the result of someone planting deliberate false flags.
One of the most famous examples was the Olympic Destroyer malware used in the PyeongChang Winter Olympics attack in 2018. This was initially thought to be the work of North Korea. That was in large part thanks to the efforts of Russia’s military intelligence service, the GRU, to disguise its own responsibility for the attacks and point the finger of blame elsewhere.
What can stop you accurately making attributions?
Commodity malware such as cobalt strike, living off the land, the use of LOLBINS, deliberate false flags from the threat actors. There are many things that can make attribution difficult. Often it boils down to those small things that humans do that they find hard to change.
Many years ago, when my working life was in the unix shell, I picked up a habit of storing temporary output in files with names like aaa, bbb, ccc – if you see this in your environment, I promise it was not me. Breadcrumbs like this though build up a view of actor’s behaviours to help with saying, “yes, these are the same people”.
In the ransomware world, very often the encryption operations are conducted by affiliates, franchisees if you like. Attribution at one level is straightforward if the encryption event has occurred (you have the malware) but understanding which affiliate may have been responsible is harder. Affiliate tracking is important, because at the end of the day we are looking to identify ransomware precursors, not ransomware (because it is too late at that point). Affiliates themselves are not bound to single ransomware groups either – they will go where the money is.
With some hostile state actors, there’s evidence of a Digital Quartermaster in operation. There is a group, or groups, whose mission is to supply and maintain malicious tools in support of cyber espionage operations. Tools like Shadowpad and PlugX point to Chinese groups, but they are re-used so often that other indications need to be used to cluster activities (intent/targeting, c2 clustering, sideload mechanisms etc.)
Is attribution something that CISOs and security professionals need to be concerned with?
Attribution to individuals is not important. It is for law enforcement, governments and those who are actively disrupting threat actors. But for cyber defenders, attribution to a group or “intrusion set” is sufficient.
It is important that a CISO can characterise the threat groups who may be targeting their business, which is often the most important when risk modelling. For example, GOLD CRESTWOOD (Emotet) are a large scale, highly organised criminal organisation that have been operating for over a decade, have been making money for over a decade, and aren’t going to give up. Their intent is criminal money making, and they are organised. It’s not two guys in hoodies hunched over a laptop in Russia.
It is also important for CISOs who are in industries that may be targeted by hostile state actors to ask themselves, “What do I have that others might want?” and “Who do I work with that might be targeted?”.
With hostile state actors, it is all about intent.
Recommended
- Scotland Loves Local Initiative Goes Digital
- Cybersecurity Firm Expands After NHS Scotland Contract Win
- No Evidence of Responsible AI Activity in 8 of the World’s Largest Banks
If you are the CISO of a defence contractor in the United States, or you are the CISO of a large intergovernmental organisation, it is important for you to understand and characterise who you are defending your network from. It is also important for your C-level to understand that the person who was roaming across your network was the Chinese government or the Russian government or a non-state sanctioned adversary.
From an operational perspective, all CISOs need to have an understanding of the degree of competence and professionalism of the clusters of activity. And some CISOs need to at least have that broad coupling of the intent saying, “Well, I understand why, as a pharmaceutical company, I might have bits of the Chinese government on my network looking at my drug designs”.





