Chaos Machine:
AP APT28 T28 FA FANCY NCY BEA BEAR R Co Comp mplex lex
Jason Kichen Alex Orleans
Chaos Machine: AP APT28 T28 FA FANCY NCY BEA BEAR R Co - - PowerPoint PPT Presentation
Chaos Machine: AP APT28 T28 FA FANCY NCY BEA BEAR R Co Comp mplex lex Jason Kichen Alex Orleans Disclaimers We are here speaking for/on behalf of no one but ourselves, and in no way do either of us represent the United States
Jason Kichen Alex Orleans
Disclaimers
▪ We are here speaking for/on behalf of no one but ourselves, and in no way do either of us represent the United States Government. ▪ Our analyses are based entirely on assessments of open source reporting.
@jckichen // @wylienewmark
Who We Are
@jckichen // @wylienewmark
What We’re Here to Talk About
@jckichen // @wylienewmark
How We’re Going to Do That
@jckichen // @wylienewmark
Why Should You Care
Understand dynamics in state- nexus op cycle Greater value from attribution Dividends for blue and red teams
@jckichen // @wylienewmark
Idea of Actors Existing on a Clear Spectrum
@jckichen // @wylienewmark
Highly Chaotic Highly Orderly
Reality is Messy, Not Pretty
@jckichen // @wylienewmark
Highly Chaotic Highly Orderly
Implications of a Common (Mis)conception
@jckichen // @wylienewmark
The chaotic nature of reality affects a threat actor at all levels
Collision of Chaos and State-nexus Ops
Strategic Culture
Competition Leadership Demands Domestic Politics
@jckichen // @wylienewmark
Our Case Study: GRU Units 26165 & 74455
@jckichen // @wylienewmark
Strategic Culture
@jckichen // @wylienewmark
Example: Clandestine Mentality
Organizational Cultures and Competition
@jckichen // @wylienewmark
Example: Wartime Mindset
Leadership Demands
@jckichen // @wylienewmark
Example: Praetorianism
Domestic Politics
@jckichen // @wylienewmark
Example: National pride/prestige
Chaos as Manifest in Operational Dynamics
▪ “Hang-on-tight” thinking
– In planning/timing – In execution – In post-op and/or follow-on activity – In the aftermath of compromise
▪ Adversary Optionality ▪ Operational Decisions
@jckichen // @wylienewmark
Apparent Chaotic Dynamics in Revealed Activity
@jckichen // @wylienewmark
Why All This Matters
▪ Holistic understanding of malicious activity’s drivers can deepen comprehension of an attribution’s implications ▪ Can support smarter defense across multiple lines of effort ▪ Can enhance fidelity of adversary emulation activities
@jckichen // @wylienewmark
Where Do We Go From Here?
▪ Influence of a government’s ideology ▪ Influence of pseudo- and non- governmental interests ▪ Further leveraging public research resources to analyze internal dynamics of relevant state entities
@jckichen // @wylienewmark
Jason Kichen (@jckichen) Alex Orleans (@wylienewmark)