Exploring the Implications of Shared Command-and-Control Infrastructure in Cyber Operations

Aug 05, 2026 996 views

I recently concluded a deep analysis of the command-and-control (C2) infrastructure linked to a state-aligned intrusion operation. An unexpected find transformed my approach: the malware in question resolved its C2 address through a smart contract on a public blockchain. Initial investigations pointed to one specific contract, but delving deeper uncovered a network of over two dozen identical contracts alongside several variants, all originating from the same builder and funded by approximately 30 distinct wallets.

This peculiar setup led to an intriguing distinction: while two of these wallets likely align with state interests, the remaining 28 appeared to belong to typical cybercriminals. This discovery highlights the emergence of a product that serves various customers across the cybercrime spectrum.

Understanding the Shared C2 Kit Phenomenon

The implications of utilizing a shared C2 kit are profound—it transforms how we think about attribution. Traditionally, we categorize cyber actors based on their infrastructure's unique identifiers. However, in this case, a singular C2 kit serves both a nation-state and a multitude of criminal operators. When creating fingerprints for detection, any signal I develop applies uniformly across all 30 operators, providing no clarity regarding which entity is active on a specific network.

It flips the fundamental attribution model on its head. A shared infrastructure should not be viewed as a weak signal but rather as a contradictory indicator spanning multiple unrelated actors. The increasing sophistication of operational structures suggests that state programs opt to rent their cyber capabilities instead of developing their unique technical environments. This presents a critical consideration for security operations centers (SOCs) striving to respond effectively to potential threats.

The Evidence Across Different Directives

While my case analysis contains particular insights, similar findings have been reached by researchers across various dimensions of cyber threat assessment. For instance, Mandiant has emphasized how certain Chinese actors exploit contractor-run relay networks, undermining the notion of exclusive actor-controlled infrastructures. One significant revelation is that IP addresses tied to these networks change every month, within the acquisition time of security tools, resulting in operational decay against established defenses.

Russia has followed a different path regarding infrastructure reclamation. Microsoft and Lumen recently documented operations by Turla, a group with strong ties to the FSB, as they leveraged the resources of other groups—sometimes even blurring the lines between purchased access and unauthorized exploitation. This scenario speaks volumes; if even sophisticated analysts cannot trace monetary transactions or security breaches, the notion of inferring nationality based on infrastructure becomes increasingly futile.

Interestingly, Iran operates on both ends of this spectrum, as illustrated by documented interactions between Iranian state-affiliated groups and the criminal sector. They have been noted to broker access to compromised systems, effectively concealing their identity while profiting from existing cyber vulnerabilities.

Revising Triage Approaches in Cybersecurity

While much of the discourse centers around the question of attribution, an equally pressing issue lies in triage. Most SOCs continue to assess incident severity based on presumed actor identities, which is an outdated methodology in a world where state and criminal actors increasingly share tools and strategies.

This conventional wisdom classifies a routine infostealer incident as a tier-one response, while suspected state activity dramatically escalates, invoking extensive investigation. However, this guideline is flawed. For example, the Amadey malware—a common criminal tool—acted as a delivery vehicle for an FSB backdoor in Ukraine. If an analyst categorizes Amadey solely as commodity crimeware and fails to recognize its association with state operations, they risk mischaracterizing critical intelligence activity as mere adware.

To address this challenge, three actionable changes are necessary without requiring new tools.

  • Firstly, decouple severity assessments from attribution. Focus triage on real-time analysis of what the intrusion is executing rather than relying on who might be behind it. Investigate observable factors such as access methods, persistence techniques, staging activities, exfiltration data, and the nature of impact—which are all calculable from telemetry.
  • Secondly, anchor detection efforts on stable attributes rather than transient infrastructures. Factors like event signatures, custom cipher constants, and distinctive strings remain constant even as network addresses and relay nodes change. This approach ensures consistency in detection regardless of the actor's identity.
  • Lastly, quantify your confidence levels explicitly. When tools are shared among actors, maintain a lower certainty on attribution. Clarifying this in reports is critical; an honest low assessment aids in effective decision-making far more than a confident but misguided assertion.

The evolving nature of cyber threats indicates that much of the infrastructure is no longer owned or operated by distinct entities. Once organizations recognize this reality, they can develop a more robust understanding of threats and improve their incident response strategies. I have shared my findings and the associated detection content, along with on-chain query techniques used throughout this analysis, on my GitHub page.

Source: John Rodriguez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

One C2 kit. 30 customers. 2 governments