Bottom line: An on-chain-based C2 analysis shows that roughly 30 different actors – only two of them state-linked – used the same command-and-control toolkit, rendering classic technical fingerprints useless as a basis for attribution.
An analysis of the command-and-control infrastructure behind a campaign classified as state-linked shows that the same blockchain-based C2 technique was used by roughly 30 different operators – only two of which can be tied to state programs, with the rest being ordinary criminals. For CISOs, this means that a technical fingerprint alone no longer says anything about who is actually inside their own network.
The starting point of the investigation was a piece of malware that resolved its C2 address via a smart-contract query on a public blockchain. Public reports had so far documented only a single contract. When analyzing the chain itself – rather than just the malware sample – the author found roughly two dozen byte-identical contracts as well as several variants, all of which trigger the same event and appear to have been generated by a common builder. Behind these were about 30 different operator wallets. Only two of these wallets could plausibly be tied to state programs – based on separate malware-family attribution by other researchers, not on the chain data itself. The remaining roughly 28 wallets showed behavioral patterns typical of ordinary criminals.
The article’s core argument runs counter to a widespread assumption in threat analysis: a shared C2 kit is not a weak attribution signal but an anti-signal. The more distinctive a fingerprint is for such a kit, the more reliably it groups together actors who have nothing to do with one another. The author explicitly emphasizes the limits of his own data: no operator attribution can be derived from the on-chain analysis, and a shared contract family does not imply that the customers know each other, coordinate, or share assignments. The chain only shows one builder and many buyers – not which buyers are state actors.
The author points to other cases of his own with a similar structure: in an Iran-nexus-linked botnet, it turned out that the tooling base used originated from a Russian criminal service offering that the actor had simply adopted. In several China-nexus loader analyses, attribution had to be kept at a low confidence level for the same reason, since side-loading chains and standard Cobalt Strike payloads are “commons” used jointly by both state and criminal actors. In one case, the entire payload consisted of unmodified, off-the-shelf Cobalt Strike – a binary that allows no conclusions about the sender.
The article places this finding in a broader trend: Mandiant, too, has documented from a different perspective – the network side – how China-nexus actors route operations through contractor-operated relay networks, which further undermines the concept of actor-controlled infrastructure and shortens the lifespan of classic indicators of compromise.
For security leaders, this has a practical consequence for daily SOC work: fingerprints based on shared commercial or criminal C2 kits should not be fed into alerting or reporting processes as a standalone attribution characteristic. Instead, additional, operator-specific indicators – such as behavioral patterns, target selection, or infrastructure timing – are needed to distinguish between state-directed and purely criminal campaigns before resources are allocated to incident response or reporting obligations.
Source: www.csoonline.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.