Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Threat Actors Master ‘False Flags’ Tactics To Deceive Victims And Security Teams
Articles

Threat Actors Master ‘False Flags’ Tactics To Deceive Victims And Security Teams

ISBuzz TeamBy ISBuzz TeamOctober 10, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Miniature swat team is standing on a computer keyboard guarding it from viruses, spyware and identity thieves. Computer security concept.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Targeted attackers are using an increasingly wide range of deception techniques to muddy the waters of attribution, planting ‘False Flag’ timestamps, language strings, malware, among other things, and operating under the cover of non-existent groups, according to a paper presented at Virus Bulletin by Kaspersky Lab security researchers Brian Bartholomew and Juan-Andres Guerrero-Sade.

The identity of the group behind a targeted cyber-attack is the one question everybody wants answered, despite the fact that it is difficult, if not impossible to accurately establish who the perpetrators really are. To demonstrate the growing complexity and uncertainty of attribution in today’s threat intelligence landscape, two Kaspersky Lab experts have published a paper revealing how more advanced threat actors use so-called False Flag operations to mislead victims and security researchers.

The indicators most used by researchers to suggest where attacks may originate from, together with illustrations of how a number of known threat actors have manipulated them, include:

  • Timestamps

Malware files carry a timestamp indicating when they were compiled. If enough related samples are collected it can become possible to determine the developers’ working hours, and this can suggest a general time-zone for their operations. However, such timestamps are incredibly easy to alter.

  • Language markers

Malware files often include strings and debug paths which can give an impression of the authors behind the code. The most obvious clue is the language or languages used and the level of language proficiency. Debug paths can also reveal a user name, as well as internal naming conventions for projects or campaigns. In addition, phishing documents can be riddled with metadata that can unintentionally save state information that points to an author’s actual computer.

However, threat actors can easily manipulate language markers to confuse researchers. Deceptive language clues left behind in malware by the threat actor Cloud Atlas included Arabic strings in the BlackBerry version, Hindi characters in the Android version and the words ‘JohnClerk’ in the project path for the iOS version. Despite this, many suspect the group to have an Eastern European connection. The malware used by the threat actor Wild Neutron included language strings in both Romanian and Russian.

  • Infrastructure and backend connections

Finding the actual Command and Control (C&C) servers used by malefactors is similar to finding their home address. C&C infrastructure can be costly and difficult to maintain, so even well-resourced attackers have a tendency to reuse C&C or phishing infrastructure. Backend connections can give a glimpse of the attackers if they fail to adequately anonymise internet connections when they retrieve data from an exfiltration or email server, prepare a staging or phishing server, or check in on a hacked server.

Sometimes, however, such ‘failure’ is intentional. For example, Cloud Atlas tried to confuse researchers by using IP addresses originating in South Korea.

  • Toolkits: malware, code, passwords, exploits

Although some threat actors now rely on publically available tools, many still prefer to build their own custom backdoors, lateral movement tools and exploits, which they guard extensively. The appearance of a specific malware family can therefore help researchers to home in on a threat actor.

The threat actor, Turla, decided to take advantage of this assumption when it found itself cornered inside an infected system. Instead of withdrawing its malware, it installed a rare piece of Chinese malware which communicated with infrastructure located in Beijing – completely unrelated to Turla. While the victim’s incident response team chased down the deception malware, Turla quietly uninstalled its own malware and erased all tracks from the victim’s systems.

  • Target victims

The attackers’ targets are another potentially revealing ‘tell’, but establishing an accurate connection requires skilled interpretation and analysis. In the case of Wild Neutron, for example, the victim list was so varied it only confused attribution.

Furthermore, some threat actors abuse the public desire for a clear link between the attacker and its targets, by operating under the cover of an (often non-existent) hacktivist group. This is what the Lazarus group attempted to do by presenting itself as the ‘Guardians of Peace’ when attacking Sony Pictures Entertainment in 2014. The threat actor known as Sofacy is believed by many to have implemented a similar tactic, posing as a number of hacktivitist groups.

Last, but not least, sometimes attackers try to push the blame onto other threat actors. This is the approach adopted by the so far unattributed TigerMilk actor, which signed its backdoors with the same stolen certificate previously used by Stuxnet.

“The attribution of targeted attacks is complicated, unreliable and subjective – and threat actors increasingly try to manipulate the indicators researchers rely on, further muddying the waters. We believe that accurate attribution is often almost impossible. Moreover, threat intelligence has deep and measurable value far beyond the question ‘who did it’. There is a global need to understand the top predators in the malware ecosystem and to provide robust and actionable intelligence to the organisations that want it – that should be our focus,” said Brian Bartholomew, Senior Security Researcher at Kaspersky Lab.

To learn more about how False Flags are used to confuse attribution in targeted attacks, read the blog on Securelist.com.

To learn more about Kaspersky Lab’s APT Intelligence reporting service, please visit. http://www.kaspersky.com/enterprise-security/apt-intelligence-reporting.

[su_box title=”About Kaspersky Lab” style=”noise” box_color=”#336588″][short_info id=’59584′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}