{"id":9011,"date":"2026-08-05T10:00:00","date_gmt":"2026-08-05T10:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9011"},"modified":"2026-08-05T10:00:00","modified_gmt":"2026-08-05T10:00:00","slug":"one-c2-kit-30-customers-2-governments","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9011","title":{"rendered":"One C2 kit. 30 customers. 2 governments"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running.<\/p>\n<p class=\"wp-block-paragraph\">The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I found that contract was one member of a family: Two dozen byte-identical contracts plus a set of variants, all emitting the same event, all stamped out by the same builder. Roughly 30 operator wallets were driving them.<\/p>\n<p class=\"wp-block-paragraph\">Two of those wallets are plausibly state-aligned. The other 28 or so look like ordinary crimeware.<\/p>\n<p class=\"wp-block-paragraph\">I went in looking for an actor\u2019s infrastructure. What I found was a product with a customer list.<\/p>\n<p class=\"wp-block-paragraph\">The convergence story is well covered by now, and CSO has already written about nation-state actors hiding behind criminal tooling. Most of that reporting frames it behaviorally: States are acting like crooks, running ransomware, taking payment. That\u2019s true and it isn\u2019t the part that changes my working day. The narrower thing I keep hitting in casework is structural. State programs aren\u2019t building the infrastructure they run on; they\u2019re renting it, and once you internalize that, several things your SOC does every day stop making sense.<\/p>\n<h2 class=\"wp-block-heading\">What a shared kit does to your indicators<\/h2>\n<p class=\"wp-block-paragraph\">Start with that ratio, because it\u2019s the whole argument. A state program and roughly 28 unrelated criminal operators were running the same C2 kit, from the same builder, on the same infrastructure pattern. Any fingerprint I write for that kit fires on all 30 of them and tells you nothing about which one is in your network.<\/p>\n<p class=\"wp-block-paragraph\">That inverts how most of us were trained to think. A shared kit isn\u2019t a weak attribution signal; it\u2019s an anti-signal. It pools unrelated actors under a single indicator. The more distinctive the fingerprint, the more confidently it groups people who have nothing to do with each other.<\/p>\n<p class=\"wp-block-paragraph\">The defensible read is a shared supplier with independent customers. Two government programs and a few dozen crooks sourced C2 tradecraft from the same criminal market, the way they might all buy the same commercial exploit. I want to be careful about the limits of that claim, because the data invites overreach. I make no operator-level attribution from the on-chain data at all. Nothing about a shared contract family implies the customers know each other, coordinate or share tasking. The nation-state labels attached to two of those wallets come from malware-family attribution done by other researchers on the implants riding the kit, not from anything I read off the contracts. The chain tells you there\u2019s one builder and many buyers. It doesn\u2019t tell you which buyers carry flags.<\/p>\n<p class=\"wp-block-paragraph\">The same shape keeps showing up in the malware itself. When I worked an Iranian-nexus botnet using that on-chain technique, the tooling turned out to be a Russian-origin criminal service the actor had adopted rather than invented. That\u2019s worth sitting with: A state intelligence service outsourced its C2 layer to a criminal vendor. On several China-nexus loader teardowns I\u2019ve done, I\u2019ve had to hold attribution at low confidence for the same structural reason. Side-loading chains and stock Cobalt Strike are communal property, shared across state and criminal operators alike. In one case the entire payload was off-the-shelf Cobalt Strike. There is nothing in that binary that can tell you who sent it, and any analyst claiming otherwise is reading tea leaves.<\/p>\n<h2 class=\"wp-block-heading\">The same pattern, from three other directions<\/h2>\n<p class=\"wp-block-paragraph\">I only see my own casework, so it\u2019s worth noting that researchers coming at this from completely different angles land in the same place.<\/p>\n<p class=\"wp-block-paragraph\">Mandiant approached it from the network side, documenting how China-nexus actors route operations through <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-espionage-orb-networks\">contractor-run relay networks<\/a> that undermine the whole concept of actor-controlled infrastructure. Their point about indicator lifespan is the one defenders should sit with: A node\u2019s IP address can cycle out in about a month, so any blocklist built on it is decaying before you finish writing the ticket.<\/p>\n<p class=\"wp-block-paragraph\">Russia gets there by a different route again. Microsoft and Lumen documented Turla, an FSB-linked group, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/12\/11\/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine\/\">riding other actors\u2019 infrastructure outright<\/a>, including commodity Amadey bots, to deliver its own backdoors onto Ukrainian military targets. The detail I find clarifying is that their analysts couldn\u2019t determine whether Turla had paid for the access or simply broken into the criminal panels. When the pros can\u2019t tell purchase from theft, the idea that you\u2019ll infer nationality from infrastructure is finished.<\/p>\n<p class=\"wp-block-paragraph\">Iran shows up on both sides of the market. CISA, the FBI and DC3 documented an Iranian state-linked group <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa24-241a\">working the criminal underground as an access broker<\/a>, selling footholds to ransomware affiliates for a cut and hiding its own nationality from its customers.<\/p>\n<p class=\"wp-block-paragraph\">The motives differ, and that\u2019s the interesting part. Iran and North Korea buy, because sanctions leave them shopping in a market they don\u2019t control. China subcontracts to a domestic industry that exists for the purpose. Russia mostly takes what it wants from actors already in the neighborhood. Four routes, one destination: There is no operator-owned infrastructure left for you to find.<\/p>\n<h2 class=\"wp-block-heading\">Why this breaks your triage, not just your attribution<\/h2>\n<p class=\"wp-block-paragraph\">Attribution is the part everyone talks about. Triage is the part that costs you money, and almost nobody has updated it.<\/p>\n<p class=\"wp-block-paragraph\">Most SOCs route severity partly on presumed actor, whether or not anyone wrote it down. Commodity infostealer on a workstation gets a tier-one ticket and a reimage. Suspected state activity gets escalated, gets the retainer call, gets the full hunt. That rule is reasonable, it\u2019s close to universal and it rests on an assumption that no longer holds: That tooling correlates with actor.<\/p>\n<p class=\"wp-block-paragraph\">Watch what that assumption does. Amadey is textbook commodity crimeware, and in Ukraine it was the delivery vehicle for an FSB backdoor. Play ransomware is a criminal operation, and Unit 42 found a North Korean state group operating inside a Play incident. If your rule is \u201cAmadey is commodity, close it,\u201d you closed an intelligence service\u2019s operation and filed it as adware.<\/p>\n<p class=\"wp-block-paragraph\">So, three changes, and none of them need new tooling.<\/p>\n<p class=\"wp-block-paragraph\">Sever severity from attribution. Triage on what the intrusion is doing, not on who you think owns it. Access, persistence, staging, exfiltration and impact are all observable in your telemetry. The operator\u2019s nationality isn\u2019t, certainly not at the moment you have to make the call. Commodity tooling must stop functioning as a de-escalation signal on a host that matters.<\/p>\n<p class=\"wp-block-paragraph\">Anchor detections on the durable constants rather than the infrastructure. Rented addresses rotate, relay nodes cycle monthly, on-chain C2 repoints for about the price of a coffee. What doesn\u2019t move is the technical fingerprint of the kit: The event signature, a custom cipher\u2019s modified constants, a specific side-load chain, a distinctive string table. Those survive rotation. Build there, and accept that the same rule will fire on a nation-state and a teenager both.<\/p>\n<p class=\"wp-block-paragraph\">Cap your confidence and put the number in writing. When tooling is communal, tooling-based attribution is worth low confidence at best. Say so in the report. An honest low is more useful than a confident guess, because people make decisions on what you write.<\/p>\n<p class=\"wp-block-paragraph\">The infrastructure was never going to tell you who they are. It isn\u2019t theirs. Once you stop asking it that question, it becomes a much more useful piece of evidence.<\/p>\n<p class=\"wp-block-paragraph\">I\u2019ve published the detection content and the on-chain queries from this work on <a href=\"https:\/\/github.com\/yankywilson\">my GitHub<\/a>.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>I was mapping the command-and-control infrastructure behind a state-linked intrusion set when the query came back and effectively ended the exercise I thought I was running. The malware resolved its C2 address by reading a smart contract on a public blockchain. Public reporting described one contract. Working from the chain rather than the sample, I [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9012,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9011","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9011"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9011"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9011\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9012"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}