Member Login Become a Member
Advertisement

Claiming the Kill: Attribution and False-Flagging in Cyber Offense

  |  
09.18.2026 at 06:00am
Claiming the Kill: Attribution and False-Flagging in Cyber Offense Image

Abstract

In this article, we highlight the roles of attribution and false-flagging in cyber offense operations. Drawing from theory and real-world examples, we show that these reflect decisions aligned with strategic identity management, shaped by considerations of incentive and liability, and that they serve as more than situation-specific operational tools. Specifically, we present three short case studies on actor-specific “cyber kill” behaviors, showing that credit is likely to be claimed when incentives are high both operationally and reputationally, and that credit is likely to be discarded or reassigned when the anticipated liability is high.


Introduction

Operations in organized predatory crime carry the decision of attribution for the actor(s) involved – whether or not to claim credit. In the context of the kill chain in cybersecurity, attribution is defined as “determining the identity or location of an attacker or an attacker’s intermediary.” It is, in many ways, a managed variable depending on what the actor makes of it. While some actors publicly communicate their identity and other details, others may conceal themselves, fully or behind another’s visible identity, and some operations may involve concealment and revelation at different stages. The false flag is a common tool of deception and irregular warfare, used in both covert offense and conventional military operations to avoid blame while implicating another party. World War II involved several such false-flag incidents, including an attack by German operatives disguised as Polish soldiers on a radio station on the German-Polish border, which gave Hitler a pretext to invade Poland.

Misattribution behaviors are particularly common in organized crime. In certain types of crimes at sea, this is operationalized by “flags of convenience” that allow a vessel’s registered nationality to be legally and functionally detached from its true ownership, leading some vessel owners to deliberately select flags of other states that do not cooperate with legal fishing regulations, or to use such false flags to evade detection (e.g., a notable 2018 tanker case of sanction evasion involving North Korea). Mexican cartels are known to stage narco-messages and narco-propaganda at the site of killings, both with correct attribution to threaten rivals and claim territory, and with misattribution to deflect blame onto competing organizations. Denying responsibility for their operatives’ violence is common among terror organizations, while another terrorism study suggests that claiming credit and claiming earned or false credit are distinct behavioral decisions shaped by situational and competitive factors.

In organized cybercrime, strategic misattribution is commonly used by ransomware syndicates that operate branded leak sites as part of their operations, even as they maintain fluid identities characterized by frequent rebranding, exit-scamming, and identity-laundering to confuse law enforcement and victims. For instance, what appeared to be the death of ALPHV/BlackCat was later found to be a scam. False-flagging in offensive cyber operations may be exhibited more strongly by state actors. For instance, the 2018 Olympic Destroyer malware was deployed during the PyeongChang Winter Olympics in South Korea, planting code artifacts matching North Korea’s Lazarus Group, in a deception that was ultimately linked back to Russia’s GRU.

In this concept article, we focus on attribution and false-flagging in organized cybercrime, viewed through the lens of strategic identity management. We argue that these reflect actor-specific behaviors rather than situation-specific operational tactics alone, and that these decisions are shaped by considerations of incentive and liability. Through three real-world case studies, we show that actors claim credit when incentives are high both operationally and reputationally, and that they falsely discard or deflect credit when the anticipated liability is high. This incentive-versus-liability structure can help cyber defense practitioners map actor-specific behaviors of claiming credit and false-flagging, possibly at different stages within their typical kill chain.

A Concept of Strategic Identity Management

Sociology offers one of the foundational theories of identity management. In 1959, Goffman proposed that identity is not a fixed internal fact; rather, it is a managed, situational performance in which a front-stage public persona is actively curated for a given audience, while concealing or withholding a back-stage private self. In this dramaturgical framing, something like a ransomware group rebranding can be viewed as a deliberate curation of a front-stage identity that may be borrowed, fabricated, replaced, or discarded to control what an audience (e.g., a victim, a regulator, an investigator, a rival) is allowed to know.

This framing is supported by classical deception theory, particularly the complementary mechanisms of “simulation” and “dissimulation.” Acts of simulation (i.e., mimicking, inventing, decoying) work to hide what is real, while dissimulation mechanisms (i.e., masking, repackaging, dazzling) can be used to reveal false or fabricated information. Viewed through this combined lens, a false-flag operation allows an actor to stay hidden under a borrowed or manufactured identity. Strategically, this can offer an organized criminal actor several situational benefits, as noted earlier, ranging from financial gain, political gain, reputational or territorial standing, coercion, or deterrence; it also helps offset its operational liability (e.g., reputational damage, retaliation, fines, prosecution, sanctions, among others) with either ambiguous attribution or complete misattribution to a different actor. In the case of organized cybercrime, this strategic value is further enhanced by several infrastructure considerations specific to the cyberworld that lower the cost of identity manipulation. For instance, it is easy for a ransomware actor to anonymously rent an IP address, plant and reuse code from other actors’ toolkits, or use false linguistic or temporal artifacts to mislead forensic analysts.

In the Q Model framing, cyber attribution among state and criminal actors is a complex political process, in which the actor’s confidence in an attribution runs along a spectrum rather than a simple yes/no decision. This can explain why organized cybercrime actors tend to treat attribution as a contestable and manageable variable, rather than as a fixed artifact to be discovered. This is particularly relevant for ransomware operations, where payloads are shared, leaked, and resold across affiliate networks, where attribution is frequently claimed or revealed on leak-sites controlled by the “brand,” and where multiple “rebranding” cycles are used by major actors for continuity of existence. Ransomware attribution-based actions that deserve special attention include those that claim credit when the incident damages the reputation of an adversary, those that stage exit scams to avoid law enforcement detection, and those that evolve to shed life-course liability.

 Case Studies from Cyber Offense

1. Nationalism, Profit, Tradecraft Commons

In November 2014, Lazarus Group, a designated Advanced Persistent Threat (APT) state-actor, breached Sony Pictures before the screening of the movie The Interview, which appeared to ridicule the North Korean leader. While the group publicly claimed credit for the intrusion under the moniker “Guardians of Peace” in their data leak and coercive threats against theaters to cancel the film release, their malware was found tied to an earlier Lazarus-linked DarkSeoul attack on South Korean banks and media. In contrast, the group carried out its 2016 Bangladesh Bank heist with zero publicity and absolute stealth, over a nearly year-long operation to gain access, discover and compromise SWIFT credentials, deploy wiper malware to delete their footprint, and ultimately attempt to steal nearly $1 billion while eventually stealing $81 million. In other instances, the group has been documented to use false flags, particularly implying Russian and Chinese involvement.

2. Borrowed Affiliation, Distributed Deniability

Indonesia’s Muslim Cyber Army (MCA) case illustrates classic dissimulation and simulation techniques. An unknown entity in 2018, when they started coordinated disinformation operations to destabilize the sitting president, they borrowed Anonymous’ imagery to suggest a local affiliation rather than outright impersonation; this was reflected in their mimicking of Anonymous’ decentralized and self-declared membership model, while occasionally trading Anonymous’ emblematic Guy Fawkes mask for a keffiyeh. The dissimulation was made apparent during Indonesian Police investigations that tracked the organization to a central WhatsApp group called Family MCA, which was found to be the source of the disinformation operation. Since October 2023, the MCA memetic brand has resurfaced to conduct pro-Palestinian operations against Israeli targets, with publicly posted claim attributions alongside other names such as “Ghosts of Palestine.”

3. Flex and Flexibility

The hacktivist/ransomware collective GLORIAMIST India surfaced in 2024, and it was linked to two other brand monikers in quick succession: the first, Solntsevskaya Bratva, briefly adopted the name of a real, historically infamous Russian organized-crime syndicate, before settling on a second Russian-sounding moniker, CyberVolk (“volk” means “wolf” in Russian). While CyberVolk’s origin was traced to India, its ransom notes and messages are either written in Russian or with Russia-leaning language – a classic application of simulation operating at the level of a national identity, first flexing the clout of a real Russian mafia group and later relying on the clout associated with Russian organized cybercrime. The concealment is seen to reverse once the group turns to sale and monetization, where it reportedly advertises the low-cost advantage of its ransomware-as-a-service source code.

Discussion and Conclusion

In organized cybercrime, identity appears to function as a brand asset with fluctuating and context-specific strategic value. Broadly, key motivations incentivizing false-flagging and selective identity portrayal differ between new and established cybercrime groups; these span reputation, legitimacy, political signaling, financial leverage over victims, and marketing, among others. On the other hand, all three case studies displayed elements of concealment in varying degrees, albeit with greater convergence on the underlying motivation, which was primarily to mislead or avoid law enforcement in some capacity.

Borrowing or implying affiliation with established, more powerful groups likely helped newcomers like MCA and GLORIAMIST benefit from the name-brand value that they themselves had yet to earn; however, the incentives were likely quite different for these actors. MCA’s selective appropriation of Anonymous imagery may have been incentivized by its need to signal political and moral high ground, typically associated with the Anonymous brand. On the other hand, GLORIAMIST’s specific gravitation toward publicly revealing Russian branding during their attack mirrors the behavior of other new groups. Such an association may signal tacit Russian state protection from arrests initiated by other states, as well as enhance coercive power over victims by implying the threat of Russian organized crime.

We recognize there could be alternative explanations in both of these examples. In the case of MCA, multiple administrators were involved in creating content, possibly with different stylistic preferences for symbolism and imagery, and the diffuse memetic content may reflect brand-crafting decisions rather than calculated simulation or dissimulation; this helped MCA achieve both ambiguity in attribution and reinforcement of their group’s specific claim. On the other hand, GLORIAMIST may fit a documented pattern of a broader Russian government performance of global hacktivist collectives, to distract Western agencies and organizations with real and imagined attacks on their infrastructure and policies. GLORIAMIST’s claimed Indian origin rests on a single unverified alias (“Hacker-K”), without confirmation of the group’s actual location or structure, and with only limited references to India and use of memetic hacktivist content to satisfy the storyline. Rather than speculating, we are highlighting the breadth of folkloric threat narratives that threat actors can use for false-flag attribution, particularly what appear to be the incentives driving their attacks.

These possible incentives must also be considered in tandem with the liability of mimicking or free-riding on bigger-name brands without their permission, or of deviating from the tacit “rules” these established groups enforce to sustain their own reputation. These reactions can range from anger and public disaffiliation (LockBit’s public statement to distance themselves from an affiliate’s attacks on a hospital) to insider dissent and leakage (e.g., the Conti “Panama papers of ransomware,” comprising chat logs and source code leaked by a disgruntled member unhappy with the group’s recent public alignment with the Russian government’s invasion of Ukraine). While the specific dynamics of new-versus-old retribution need further study, what emerges more clearly is the incentive-versus-liability calculation associated with false-flagging and identity manipulation by newcomers in the organized cybercrime ecosystem – where liability is posed by law enforcement as well as other criminal actors.

In the case of more mature groups, exemplified by Lazarus Group in this article, reputation and credentials are already-earned brand assets. Lazarus is a particularly interesting group, for two reasons: (1) it is a known state actor linked with a wide variety of exploits, including espionage, and (2) like the sanctioned state it supports, it operates largely in stealth, punctuated by rare bursts of highly visible publicity. This makes their Sony Pictures attack a case worth studying with more seriousness, given the multiple incentives seemingly in deviation from their usual operational preference for concealment; it is a particularly noteworthy case study of nationalism, political signaling of high moral ground, reputation management, and purely coercive (rather than financially coercive) power over a high-profile target.

Lazarus’ typical stealth operations as a state actor (especially instances in which they have masqueraded as another state actor, or vice versa) create much ambiguity for the targeted states. In a sense, this form of ambiguity in state-actor cyber offense false-flagging may be viewed as a weaponized tool for cognitive warfare. A society that cannot say with certainty who attacked it is one whose response, credibility, and public morale are all degraded simultaneously, in addition to the cost of the disruption. On the other hand, misattribution under conditions of adversarial uncertainty can also insert liability in false-flagging, which “can serve as a destabilizing tool, blurring red lines and fostering mistrust among major powers.”

For cyber defense practitioners, the study of identity attribution, especially false-flagging, as a strategic behavioral pattern can help identify underlying incentive-versus-liability considerations, and these can be further informed by credit-claiming dynamics seen in other organized crime categories. Actors are likely to claim earned or unearned credit when reputation is an asset, largely to demonstrate and market their capability, to signal influence or political positions, or to leverage coercive power for financial or political gain; they are likely to disown or reassign identity when reputation becomes a liability, especially involving risk of law enforcement pressure, sanctions exposure, and other retribution. We may even reframe these operational and geopolitical environments as vulnerabilities for cyber offense actors.

The same breadth of analysis we seek in actor attribution, mapping the tools and techniques used by these actors, should be applied to the analysis of formal and informal group dynamics within their organized collectives or enterprises. We can generally say that the established stages and actions consistently performed by organized cybercriminals present a behavioral, and not merely technical, map of their anticipated decision-making. This map includes the naturalistic factors at play when these threat actors experience success, failure, or complications along the way, whether those complications are public accusations or law enforcement efforts. Recognizing which incentive or liability shapes the calculus of such strategic identity manipulation in the cyber kill chain is what makes attribution and false-flagging important, with implications for cyber deception strategy and cyber defense in general.

About The Authors

  • Mira Das
    Mira Das is a doctoral researcher and social scientist affiliated with John Jay College of Criminal Justice. Her interests include cybercrime, organized and group crime, and the analysis of behaviors, systems, and structures in crime and law enforcement. Mira is based in New York, having earned a Ph.D. in Criminal Justice from the City University of New York.

     

    View all posts
  • Tim Pappa

    Tim Pappa is a Staff Incident Response Engineer - Cyber Deception Strategy, Content Development, and Marketing, Cyber Deception Operations, Walmart Global Tech.  Previously, Tim was a Supervisory Special Agent and profiler with the Federal Bureau of Investigation’s (FBI) Behavioral Analysis Unit (BAU). Tim is currently an Industry Fellow at Yale University’s Digital Ethics Center. Tim is writing No Starch Press’s first book on cyber deception.

    LinkedIn: https://www.linkedin.com/in/timpappa

    View all posts

Article Discussion:

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted