Behavioral and Propagation-Based Analysis of APT Attacks for Effective Attack Attribution
At a glance
- Citations
- 2
- References
- 0
- Comments
- 0
Abstract
Various advanced persistent threat (APT) groups are emerging with different tactics, techniques, and procedures (TTPs) for targeting enterprises and organizations. Traditional methods that use either static or dynamic analysis might struggle to detect polymorphic and packed zero-day attacks. In this paper, we propose an approach that allows mal ware analysts to consider all aspects of an attack, including not just sample analysis but also a view into TTP-based attack vectors. By correlating observed TTPs with known threat intelligence, our approach facilitates attack attribution, helping analysts identify the threat actor behind an attack campaign. We applied our approach to a recent APT attack by the Black Basta group on Keytronics, which utilized unique delivery mechanisms for initial access. This paper then describes the entire attack vector, explaining how email bombing was used to deliver payloads like SystemBC and Black Basta ransomware. We also list the indicators of compromise, command and control traffic, persistence mechanisms, detection rules, and other unique identifiers from this attack campaign. By integrating sample-based analysis with TTP-based attack vector examination, our approach enhances existing attribution methods, providing a more comprehensive perspective on APT attack strategies.
Publication details
- DOI
- 10.1109/isdfs65363.2025.11012042
- OpenAlex
- W4411208121
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.