Lesson 1 of 1 Β· 25 min read

Building and Maintaining Threat Actor Profiles

A threat actor profile is only as good as its evidence base. Precision without evidence is fiction; uncertainty acknowledged is honest intelligence.


Threat Actor Profile Template

# THREAT ACTOR PROFILE
**Classification**: TLP:AMBER β€” Authorized recipients only
**Version**: 1.0 | **Last Updated**: 2024-09-01
**Profile Author**: [Your name/team]

---

## Summary
[2-3 sentence overview: who this actor is, what they do, why they matter to your organization]

## Identity
| Field | Value | Confidence |
|-------|-------|------------|
| Primary name | APT29 | High |
| Aliases | Cozy Bear, IRON HEMLOCK, Midnight Blizzard, Nobelium | High |
| Suspected sponsoring nation | Russia (SVR) | Moderate |
| Type | Nation-state | High |
| Motivation | Espionage | High |

## Targeting Profile
| Field | Value | Confidence |
|-------|-------|------------|
| Primary industries | Government, defense, think tanks, political | High |
| Geographic focus | Western Europe, North America, NATO members | High |
| Typical victims | Foreign policy organizations, intelligence targets | High |
| Relevance to us | [Assess whether this actor targets organizations like ours] | |

## Tactics, Techniques, and Procedures
### Initial Access
- T1566.002 Spearphishing Link [High confidence β€” documented in 5+ campaigns]
- T1195.002 Compromise Software Supply Chain [High β€” SolarWinds]
- T1078 Valid Accounts (stolen credentials via phishing) [High]

### Execution
- T1059.001 PowerShell [High]
- T1059.003 Windows Command Shell [Moderate]

### Persistence
- T1053.005 Scheduled Task [High]
- T1547.001 Registry Run Keys [Moderate]

[... continue for all tactics ...]

## Malware and Tools
| Tool | Type | Confidence | Notes |
|------|------|------------|-------|
| SUNBURST | Custom backdoor | High | SolarWinds supply chain |
| TEARDROP | Custom dropper | High | Post-SUNBURST payload |
| Cobalt Strike | Commercial | Moderate | Shared with many actors |
| MagicWeb | Custom ADFS backdoor | High | Attributed in 2022 |

## Infrastructure Patterns
- Hosting: Legitimate cloud services (Azure, AWS) for C2 blending
- Domain pattern: Typosquatting of target organization's third-party services
- Certificate: Let's Encrypt with target-relevant domain names
- Infrastructure lifecycle: Short-lived per operation; rotate after exposure

## Operational Patterns
- Active hours: Primarily UTC+3 business hours (Moscow timezone)
- Dwell time: Months to years (patience for high-value targets)
- Operational security: High β€” actively monitor for detection, change TTPs on discovery

## Known Campaigns
| Campaign | Dates | Victims | Objective |
|----------|-------|---------|-----------|
| SolarWinds | Oct 2019–Jan 2021 | 18,000+ orgs (100 targeted) | Espionage/access |
| USAID phishing | May 2021 | NGOs, government | Credential theft |
| MagicWeb | 2022 | NATO-member governments | Persistent ADFS access |

## Intelligence Gaps
- Post-compromise tooling for newer campaigns: observed initial access, 
  limited visibility into full attack chains since 2022
- Infrastructure creation pipeline: how and where infrastructure is procured
- Full victim list: confirmed victims are a fraction of likely targets

## Sources
- [Mandiant APT29 profile URL]
- [Microsoft MSTIC Midnight Blizzard reporting]
- [CISA/NSA joint advisories]