Without the ability to perform offensive counter-operations, or the aid of significant SIGINT capabilities, 99 percent of private companies lack the ability to do true attribution to the operator level of cyber attacks. This difficulty is especially exacerbated when trying to analyze disjoint malware artifacts from the exploit life cycle. That is to say, even when a skilled malware analyst is handed an executable file out of context, it is difficult or impossible for him or her to say whether the attacker was Hyun-soo Kim, Ivo Russinov, or Edward Snowden. Most non-government organizations simply lack the situational G2 and knowledge of adversary TTPs to confidently (or at least, accurately) point the finger at a specific actor, or frankly, even a nation-state. Most of this reality is due to the fact that they can only see the small subset of malware that a) has been used against them, and b) that they can detect. That being said, when examining attacks within their full context - from targeting, to attacking, to the installation of long term implants, to lateral movement, and finally to data exfiltration - certain tippers can be gleaned from technical artifacts left in each stage that help paint the picture in broad strokes.
Malware is truly a global problem, but when it comes to targeted intrusions, the common factor involved in all aspects is the human one. A human did the reconnaissance on the target, a human sent the email, and a human developed or at least compiled the payload being used against the target. Often times humans make mistakes - especially when they are overly careless due to not being particularly concerned about blowback if they are caught. Mistakes such as leaving in the keyboard layout used to send an email, compile paths in a payload, CnC domain registration details, fonts, IP SWIPing, and others can all be used as loose technical indicators to lump multiple campaigns into different buckets. Although this FireEye report cannot help identify a specific person at the keyboard inside 4th PLA, the Syrian Electronic Army, or the al-Qassam Cyber Warriors, hopefully the methods mentioned can help cyber defenders group multiple attacks together to do technical attribution to a specific group, so that the targets can begin to profile the various threat actors who are making persistent intrusion attempts against them.
General Alexander, DIRNSA, recently remarked “who is taking our data … and why? …. that is a question I believe the American people expect me to be able to know.“ You are being attacked for a reason, and if the attacks stop, ask yourself why it is crucial. Either they’re already inside your network, they were able to steal the information from another party, or the time-sensitive nature of the information rendered the attack fruitless. There is significant value in knowing your attackers, what they are after, and whether the attacks being lobbed at your organization were targeted or opportunistic.
For more on this topic, read the just-released FireEye report here.

