343 Angry Spark
Welcome to Memetic Warfare.
Bill Marczak of Citizen Lab - an organization that does some excellent technical research, if I’m not always on board with some of their editorial and political bends - published some incredible research into seemingly Western cyber tooling, available here.
You can and should read this as it shows how an opsec error on the part of the operators enabled Marczak and his researchers to use the IPv4 “Record Route” feature to uncover the true C2 infra used by the operators. It’s a great learning piece for those interested in not only domain and infra analysis.
Marczak muses that the operation is tied to the UK, with the tooling being joint US-UK due to ties to Operation Triangulation.
So far all well and good, but what’s more relevant to readers of this blog is the IO component. He notes that a BreachForums user, IGrooEagle, posted leaked data from Kaspersky in October of 2023.
IgrooEagle gave away, as Marczak said, “the most interesting ones for free”, meaning SNORT and other rules used to detect APT organiations worldwide, burning Kaspersky’s visibility into them as well as their reputation of course. Note that this is after Kaspersky published first on operation Triangulation in June of 2023.
If I had to hazard a guess - I’d say that this was a Western hack and leak. Some presumably Western state had already popped Kaspersky and began leaking their secrets online via KasperSekrets on Twitter - see below:
At this point, if I’m the operator behind operation Triangulation, I’d think the following: OK, they got me with that one and have burned my C2 and tooling, our infrastructure has to be replaced.
Let’s now use that exposure and publish all of their rules that they have on APT groups worldwide to roll up their operations. We could then use our own leaked ones, which only expose some infrastructure and not tooling or TTPs that cost us a lot to reconstitute, to gain legitimacy and deflect attribution from us.
Some real 4-d chess here from whoever is running this, assuming, of course that I’m right and that this is a cyber-enabled influence operation against Kaspersky.
I’d also like to shout out Channel News Asia for a great investigation into a Chinese virtual espionage operation targeting Singapore - check it out here. They were smart and reached out to friend of the blog Max Lesser to give some insight, so read it there.
That’s it for this week, thanks for reading.




