The State Cyber Ecosystem
Map services, military units, contractors, criminals, hacktivists, vendors, and access brokers as distinct relationships.
In this lesson, you will learn to:
- Produce an actor-relationship map that separates evidence of capability, coordination, sponsorship, and legal attribution.
The State Cyber Ecosystem
This lesson replaces the single-actor box with an ecosystem model. It focuses on what states gain and lose through delegation, procurement, tolerance, and covert control.
Separate operator, sponsor, beneficiary, and controller
A state-linked campaign may involve an intelligence requirement set by one institution, access obtained by a contractor, infrastructure rented from criminals, tooling shared across units, and public amplification by nominal volunteers. “APT X did it” compresses those relationships and can mislead response decisions.
Analyze at least six roles: strategic beneficiary, directing authority, operational command, technical operator, capability or access supplier, and amplifier. For every edge, label the evidence and possible relationship: commanded, contracted, coordinated, tolerated, coerced, copied, or merely aligned. A government can benefit from conduct without directing it; a criminal can be state-tasked for one operation while remaining profit-driven elsewhere.
Delegation offers scale, special skills, low cost, and deniability. It also creates control risk, poor discipline, intelligence leakage, unpredictable targeting, and escalation. Google’s analysis of the cybercrime–state nexus describes states purchasing credentials, malware, and services from mature criminal markets. Treat this as a supply system: disruption can target trust, payments, hosting, recruitment, or access quality rather than only named malware.
Proxies create political and operational friction
Proxy is not a synonym for “actor we suspect.” It describes a relationship in which one party uses another to pursue objectives while preserving some separation. That relationship may change over time and by operation. Assess command and control, financing, tasking, target consistency, safe haven, shared infrastructure, personnel overlap, and reaction to state priorities.
Distinguish attribution for intelligence from attribution for state responsibility. Technical and behavioral evidence may strongly associate an intrusion with a cluster. Evidence that a state organ directed or controlled the conduct is a different proposition. The ICRC’s position paper summarizes recognized routes by which conduct can be attributable to a state, including state organs, empowered entities, instructed or controlled groups, and conduct later acknowledged and adopted by the state.
Operationally, proxies complicate signaling. A victim may be unsure whether activity is authorized, tolerated, or uncontrolled. A proxy may exceed sponsor intent. A public response aimed at the state can strengthen a deniable narrative; a response aimed only at infrastructure may leave the sponsor’s incentives unchanged. Build response options against each relationship, then identify what evidence would justify moving up the chain.
Track the ecosystem as a living order of battle
Maintain an actor order of battle that records units, personas, suppliers, infrastructure, capability families, target sets, working rhythms, command changes, and confidence. Preserve vendor names as aliases rather than assuming one-to-one identity. Different vendors cluster telemetry differently; a shared label can hide multiple teams, while separate labels can describe overlapping activity.
Update the model when relationships change, not only when indicators change. Watch recruitment, company registrations, sanctions and indictments, procurement, conference publications, malware-market adoption, infrastructure shifts, and new mission priorities. Record gaps and disconfirming evidence. The goal is to anticipate capacity and tasking, not maintain a decorative threat-actor chart.
Resources
- Cybercrime as a Multifaceted National Security Threat — Google Threat Intelligence analysis of criminal markets, state customers, low-equity tooling, and deniable capacity.
- ICRC Position on IHL and Cyber Operations — Includes a concise treatment of attribution of conduct to states as well as humanitarian protections.