Chaos Machine: AP APT28 T28 FA FANCY NCY BEA BEAR R Co Comp mplex lex Jason Kichen Alex Orleans
Disclaimers ▪ We are here speaking for/on behalf of no one but ourselves, and in no way do either of us represent the United States Government. ▪ Our analyses are based entirely on assessments of open source reporting. @jckichen // @wylienewmark
Who We Are @jckichen // @wylienewmark
What We’re Here to Talk About @jckichen // @wylienewmark
How We’re Going to Do That @jckichen // @wylienewmark
Why Should You Care Understand Greater Dividends dynamics in state- value from for blue and nexus op cycle attribution red teams @jckichen // @wylienewmark
Idea of Actors Existing on a Clear Spectrum Highly Chaotic Highly Orderly @jckichen // @wylienewmark
Reality is Messy, Not Pretty Highly Chaotic Highly Orderly @jckichen // @wylienewmark
Implications of a Common (Mis)conception The chaotic nature of reality affects a threat actor at all levels @jckichen // @wylienewmark
Collision of Chaos and State-nexus Ops Strategic Culture Org. Cultures/ Competition Leadership Demands Domestic Politics @jckichen // @wylienewmark
Our Case Study: GRU Units 26165 & 74455 @jckichen // @wylienewmark
Strategic Culture Example: Clandestine Mentality @jckichen // @wylienewmark
Organizational Cultures and Competition Example: Wartime Mindset @jckichen // @wylienewmark
Leadership Demands Example: Praetorianism @jckichen // @wylienewmark
Domestic Politics Example: National pride/prestige @jckichen // @wylienewmark
Chaos as Manifest in Operational Dynamics ▪ “Hang -on- tight” thinking – In planning/timing – In execution – In post-op and/or follow-on activity – In the aftermath of compromise ▪ Adversary Optionality ▪ Operational Decisions @jckichen // @wylienewmark
Apparent Chaotic Dynamics in Revealed Activity @jckichen // @wylienewmark
Why All This Matters ▪ Holistic understanding of malicious activity’s drivers can deepen comprehension of an attribution’s implications ▪ Can support smarter defense across multiple lines of effort ▪ Can enhance fidelity of adversary emulation activities @jckichen // @wylienewmark
Where Do We Go From Here? ▪ Influence of a government’s ideology ▪ Influence of pseudo- and non- governmental interests ▪ Further leveraging public research resources to analyze internal dynamics of relevant state entities @jckichen // @wylienewmark
Jason Kichen (@jckichen) Alex Orleans (@wylienewmark)
Recommend
More recommend