ILLUSTRATIVE · FICTIONAL CLUSTER · SYNTHETIC DATA · ANALYST DECISION SUPPORT, NAMES NO ACTOR & NOT AN ATTRIBUTION
Evidenx does not score, attribute, or name an actor. This card clusters indicators and structures the competing attributions to support the reviewing analyst, who makes the attribution and assigns any confidence under the applicable policy.
Step 1 of 8Scope & signal reduction
What the profiling task assembled
A set of intrusions against a fictional target sector was worked as an intrusion-set profiling task. Six classes of indicator were assembled and organised into one activity cluster and a set of competing attributions to support the reviewing analyst. Nothing is discarded. Each indicator remains an observation with its provenance; this layer clusters and structures overlap, it does not name an actor.
~52
indicators across 6 classes
→
1
activity cluster (CL-STARLING-207)
→
4
attributions weighed
Malware samples
sandboxed
3 related implants
C2 infrastructure
31 nodes
domains + IPs
TLS certificates
18 certs
cert transparency
Code artifacts
several
PDB paths, strings
Build/runtime metadata
aggregate
timestamps, locale
Public reporting
6 sources
vendor + OSINT
Step 2 of 8The activity picture
A cluster, not an attribution
Working cluster:
CL-STARLING-207, three related implants sharing a custom packer and a common C2 protocol, resolving to overlapping infrastructure, targeting one sector. The cluster's tradecraft is
consistent with a publicly profiled actor pattern (evoked here as an illustrative reference). This is a
structured activity cluster to support the analyst's assessment. It is
not an attribution, and it names no group, nation, or person.
framed againstTTP reference profile (illustrative, Mandiant-style)ATT&CK technique set
evidence inmalware infra certs code
The TTP reference profile is the threat-intel analogue of the DFIR reference lists, authored and curated by an intel SME, not by this tool. Clustering is not attribution. That the tradecraft is 'consistent with' a known profile is a similarity statement carried with its basis; it is never silently upgraded to 'is that actor'.
Step 3 of 8Pertinent findings
Indicator overlap for the analyst to interpret
Custom packer reuse
identity
The same non-public packer appears across all three samples and matches samples in prior public reporting. Strong linkage between the samples; it links them to each other, not to a named operator.
C2 protocol + infra overlap
spatial
A distinctive C2 handshake and re-used hosting ranges and registrant patterns tie the samples to one infrastructure set. Infrastructure can be shared, leased, or resold. It is surfaced as overlap, not ownership.
PDB path + build locale
identity
A developer PDB path and a non-default build locale recur across samples. A pertinent authorship signal, and precisely the kind of artifact that is trivial to fake, so it is recorded as consistent-with, weighted by how forgeable it is.
Operational tempo
temporal
Compile and C2-activity timestamps cluster in a consistent daily window. Suggestive of a working-hours pattern; a working pattern is context for the analyst, not a geolocation.
Each item is a neutral indicator plus why it was surfaced, with provenance and forgeability retained. Two sources agreeing is corroboration only if they are independent, and shared tooling, shared infrastructure, and planted artifacts break independence. That fragility is recorded, not assumed away.
Step 4 of 8Timeline
Reporting, builds, infra & overlaps
T-14 mo Public vendor report profiles a similar TTP pattern (reference)reporting
T-5 mo First cluster C2 domain registered; registrant pattern notedinfra
T-4 mo Sample A compiled; custom packer + PDB path presentmalware
T-3 mo Samples B and C compiled; same packer, shared C2 protocolmalware
T-2 mo TLS certs reused across infra; cert-transparency linkagecerts
T-6 wk Third-party blog attributes a related sample to a named groupOSINT
T-3 wk Overlap found with a second cluster (possible shared hosting)infra
Step 5 of 8Attributions considered
Competing explanations, tested against the indicators
Shared / commodity tooling exclude first
The packer and C2 kit may be shared across multiple operators (sold, leaked, or reused), so the linkage could be tooling, not a single actor. The benign-for-attribution case: it must be excluded before any single-actor attribution is entertained. Turns on whether the packer is genuinely non-public.
False-flag / deliberate planting
PDB paths, locales, and timestamps are cheap to forge, and re-used infra can be chosen to mislead. Open and first-class. The more an indicator points cleanly at one actor, the more it must be checked for having been placed to do so.
Consistent-with the referenced profile
The tradecraft does overlap a publicly profiled actor pattern. Open, but 'consistent with a profile' is a TTP match, not identity; distinct groups converge on effective tradecraft. Names no group as responsible.
Mis-clustering (two activity sets)
The T-3wk overlap may mean two intrusion sets share hosting rather than one set expanding. Open; if so the cluster itself is over-merged and should be split before any attribution.
Competing attributions are held side by side and tested against the indicators, the same alternative-hypotheses machinery used in the DFIR layer. In attribution the disciplined move is to keep shared-tooling and false-flag as first-class, not footnotes. The system surfaces them; it does not choose, and it never names an actor.
Step 6 of 8Expected but not yet collected
Attribution gaps, recorded honestly
Independent confirmation the packer is non-public
not_collected
The single most load-bearing check for a single-actor claim. Until confirmed, the shared-tooling alternative cannot be excluded. Its absence carries no weight either way; it defines the collection priority.
Victim-side telemetry / EDR
not_collected
No endpoint telemetry from affected targets in hand; would corroborate hands-on-keyboard behaviour independently of the samples.
Registrant / operator identity
not_collected
Infrastructure registration is behind privacy services; the operator identity is not obtainable from open sources here, and is not inferred.
Language/authorship forensic review
absent
A qualified linguistic review of strings was sought and is not yet available; the locale signal therefore corroborates authorship only weakly, and is marked as such.
This is where attribution and Evidenx meet: not_collected (not yet obtainable) is never held against or for an attribution. It is what the collection plan is built to resolve. absent (sought and not present) is different and evidentiary. In attribution the trap is letting a clean-looking indicator stand in for the confirmation you never got; recording the gap is the guard.
Step 7 of 8Analyst support & assessment
For the analyst, not an attribution
Cluster CL-STARLING-207 links three implants by shared tooling, infrastructure, and authorship artifacts, with tradecraft consistent with a referenced profile. The shared-tooling explanation is unexcluded and flagged to check first; false-flag and mis-clustering remain open. The following is assessment support for the reviewing analyst, not an attribution, it names no actor, and it carries no confidence score.
Exclude shared tooling first
Establish whether the packer and C2 kit are genuinely non-public (retro-hunt, vendor queries, code-similarity at scale). If shared, the single-actor reading collapses and the cluster stands as a tooling family, not an actor.
Stress-test for false-flag
Treat every clean single-actor indicator as potentially planted: check PDB/locale/timestamp internal consistency and whether re-used infra was plausibly chosen to mislead.
Resolve the cluster boundary
Adjudicate the T-3wk overlap: one expanding set or two sharing hosting. Split the cluster if the evidence supports two, before any attribution language is used.
Report as a cluster, not a name
Any product refers to CL-STARLING-207 and its behaviour, with TTP overlap stated as 'consistent with' and its basis. Actor naming and confidence are the analyst's call under the org's attribution policy, not this tool's, and not stated here.
The analyst makes the attribution, assigns any confidence, and decides any reporting under the applicable attribution policy. Evidenx structures the indicators, their provenance and forgeability, and the competing attributions; it does not attribute, name an actor, or score.
Step 8 of 8Conclusion
The call is the reviewing analyst's. Evidenx stops at understanding
Evidenx has taken six classes of indicator to
data, to
information, to
understanding, the structured, corroborated, bounded picture on the preceding pages. It stops here.
The conclusion is the reviewing analyst's to make.data → information → understanding → their conclusion
Evidenx has not decided, and does not decide: attribution, the naming of an actor, or a confidence score. There is no score, rank, or confidence value in this card.
For the reviewing analyst to determine:
- Whether the cluster holds once shared-tooling is excluded.
- Which competing attributions survive scrutiny, including false-flag.
- Whether the cluster boundary should be split before any attribution.
- The attribution call, its confidence, and any reporting, under the applicable policy.
The reviewing analyst determination
Left intentionally blank. This is the reviewing analyst's conclusion to record. Evidenx provides the evidence, not the verdict.