Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should ransomware attribution be approached?

Build attribution in layers and stop at the layer supported. Malware family, service, affiliate, access broker, negotiator, infrastructure operator, wallet controller, group and individual are not interchangeable.

Combine independent evidence types

Compare malware and victim IDs, access method, commands, infrastructure, note, leak activity, negotiation, payment, provider records and seized devices. Similarity can reflect shared ransomware-as-a-service tools rather than the same controller.

Record whether external intelligence is public reporting, provider information, law-enforcement material or forensic comparison, including date, confidence and restrictions.

Preserve changing assessments

An early family match may later develop into evidence of a particular affiliate or wallet controller. Retain the reasoning and confidence at each stage rather than silently replacing conclusions.

Do not use one group label to conceal uncertain participants. If evidence supports a service but not its affiliate, or a wallet controller but not deployment, state that narrower result explicitly.

Key takeaway

Attribute ransomware at the precise operational layer supported by independent technical, provider, communication, device and financial evidence, with confidence and change history visible.

Reference: CIM-194Cyber Incidents & Offender Methods