Bottom line: An on-chain-based C2 analysis shows that around 30 different actors – only two of them state-linked – used the same command-and-control kit, rendering classic technical fingerprints useless as a basis for attribution.
An analysis of the command-and-control infrastructure behind a campaign classified as state-linked shows that the same blockchain-based C2 technique was used by around 30 different operators – only two of which can be attributed to state programs, with the rest being ordinary criminals. For CISOs, this means that a technical fingerprint alone no longer tells you anything about who is actually sitting in your network.
The starting point of the investigation was malware that resolved its C2 address via a smart contract query on a public blockchain. Public reports had so far documented only a single contract. By analyzing the chain itself – rather than just the malware sample – the author found around two dozen byte-identical contracts as well as several variants, all of which trigger the same event and appear to have been generated by a shared builder. Behind them were around 30 different operator wallets. Only two of these wallets could plausibly be attributed to state programs – based on separate malware-family attribution by other researchers, not on the chain data itself. The remaining roughly 28 wallets showed behavioral patterns typical of ordinary criminals.
The core claim of the article pushes back against a common assumption in threat analysis: a shared C2 kit is not a weak attribution signal, but an anti-signal. The more distinctive a fingerprint is for such a kit, the more reliably it groups together actors who have nothing to do with each other. The author explicitly emphasizes the limits of his own data: no operator attribution can be derived from the on-chain analysis, and a shared contract family does not imply that the customers know each other, coordinate, or share assignments. The chain only shows one builder, many buyers – not which buyers are state actors.
The author points to further cases of his own with a similar structure: in one Iran-nexus-linked botnet, it turned out that the tooling base used originated from a Russian criminal service offering that the actor had simply adopted. In several China-nexus loader analyses, attribution had to be kept at a low confidence level for the same reason, since side-loading chains and standard Cobalt Strike payloads are “commons” shared jointly by state and criminal actors alike. In one case, the entire payload consisted of unmodified, off-the-shelf Cobalt Strike – a binary that permits no conclusion about the sender.
The article places this finding within a broader trend: Mandiant, too, has documented from a different perspective – the network side – how China-nexus actors route operations through contractor-operated relay networks, which further undermines the concept of actor-controlled infrastructure and shortens the lifespan of classic indicators of compromise.
For security leaders, this has a practical consequence for day-to-day SOC work: fingerprints based on shared commercial or criminal C2 kits should not be fed into alerting or reporting processes as a standalone attribution feature. Instead, additional, operator-specific indicators are needed – such as behavioral patterns, target selection, or infrastructure timing – to distinguish between state-directed and purely criminal campaigns before resources are allocated to incident response or reporting obligations.
Source: www.csoonline.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.