What is attacker infrastructure?¶
Attacker infrastructure is the systems, accounts and services supporting malicious activity. One domain or server rarely represents the whole operation, and different components may be controlled by different people.
Assign each component a role and time¶
Map delivery hosts, phishing sites, command channels, proxies, cloud storage, staging systems, communication accounts and payment services. Record when each was active and whether it was prepared, configured or actually observed in victim traffic.
Infrastructure can rotate: one domain delivers a payload, another controls it and a third receives data. Do not assume a later address played the earlier role.
Build provider attribution cautiously¶
Preserve stable account IDs, provider and access logs, certificates, registration, payment and malware configuration. Hosting may be rented, compromised, shared or short-lived; registrant details can be false or intermediary-held.
Provider account control, operational use and personal offender identity are separate layers. Use victim-side links to prove function before moving toward human attribution.
Key takeaway
Treat attacker infrastructure as time-bound technical roles and provider accounts, distinguishing preparation, observed use, account control and personal attribution.