|
|
|
|
|
by rightbyte
834 days ago
|
|
> Attributions are about more than the code flow. You also need infrastructure to funnel exfiltrated data back to yourself. How is that even possible and how does it help? A computer is like a state machine where a minuscule amount of states are logged. When the state is gone the trace is gone. And you don't control the other involved computers anyway. And what good does accessing "exfiltrated data" do? |
|
Now you need to send the large amounts of data back to yourself, preferably without giving away your own location in the process. That’s the exfiltration phase of the cyber kill chain.
In order to do that, you’ve already established a set of listening posts and command/control sites across the internet. That’s your infrastructure. Setting that up in a pseudo anonymous way is hard, so you don’t do it often and may need to reuse it for multiple targets.
It’s that infrastructure that is hard to replicate if you’re trying to “look like” another threat actor on the Internet.