{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T06:58:19Z","timestamp":1782975499266,"version":"3.54.5"},"reference-count":92,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00215","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"4769-4787","source":"Crossref","is-referenced-by-count":0,"title":["APT to Disagree: A Comparative Analysis of Attribution in Commercial TI"],"prefix":"10.1109","author":[{"given":"Aksel","family":"Ethembabaoglu","sequence":"first","affiliation":[{"name":"Delft University of Technology,Delft,Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rolf","family":"Van Wegberg","sequence":"additional","affiliation":[{"name":"Delft University of Technology,Delft,Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yury","family":"Zhauniarovich","sequence":"additional","affiliation":[{"name":"Delft University of Technology,Delft,Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michel","family":"Van Eeten","sequence":"additional","affiliation":[{"name":"Delft University of Technology,Delft,Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Threat-Led Penetration Testing: A proactive approach to cybersecurity | Deloitte Luxembourg | Future of Advice","author":"Schubert","year":"2025"},{"key":"ref2","volume-title":"Cyber Threat Intelligence in Government: A Guide for Decision Makers and Analysts","author":"UK","year":"2019"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-150"},{"key":"ref4","volume-title":"ENISA Threat Landscape 2024 | ENISA","year":"2025"},{"key":"ref5","volume-title":"How to mature your organisation\u2019s threat intelligence capabilities","year":"2024"},{"key":"ref6","volume-title":"What is Cyber Threat Intelligence? [Beginner\u2019s Guide] - CrowdStrike","year":"2025"},{"key":"ref7","volume-title":"Google Threat Intelligence - know who\u2019s targeting you","year":"2025"},{"key":"ref8","volume-title":"CBEST Threat Intelligence-Led Assessments","year":"2025"},{"key":"ref9","volume-title":"What is Cyber Threat Intelligence?","author":"Sharing","year":"2015"},{"key":"ref10","volume-title":"Digital Operational Resilience Act (DORA) - EIOPA","year":"2025"},{"key":"ref11","year":"2025","journal-title":"TIBER-EU Targeted Threat Intelligence Report Guidance"},{"key":"ref12","volume-title":"High Stakes, Low Certainty: Evaluating the Efficacy of High-Level Indicators of Compromise in Ransomware Attribution | USENIX","author":"Van Der Horst","year":"2025"},{"key":"ref13","volume-title":"Updated advisory on potential sanctions risks for facilitating ransomware payments","year":"2021"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1080\/13523260.2019.1677324"},{"key":"ref15","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-662-61313-9","volume-title":"Attribution of Advanced Persistent Threats: How to Identify the Actors Behind Cyber-Espionage","author":"Steffens","year":"2020"},{"key":"ref16","volume-title":"Cyber Indictments and Threat Intel: Why You Should Care","author":"Nickels","year":"2019"},{"key":"ref17","volume-title":"Enterprise Detection & Response: The Pyramid of Pain","author":"Davidjbianco","year":"2013"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1080\/01402390.2014.977382"},{"key":"ref19","volume-title":"MITRE ATT&CK\u00ae"},{"key":"ref20","volume-title":"From iocs to group profiles: On the specificity of threat group behaviors in cti knowledge bases","author":"Saha","year":"2025"},{"key":"ref21","article-title":"The Evolution of Cyber Threat Intelligence (CTI): 2019 SANS CTI Survey | SANS Institute","volume-title":"SANS Institute, Tech. Rep.","author":"Institute","year":"2019"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3664476.3670870"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_7"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2808128.2808129"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_1"},{"key":"ref26","first-page":"433","article-title":"A different cup of TI? the added value of commercial threat intelligence","volume-title":"29th USENIX Security Symposium (USENIX Security 20). USENIX Association","author":"Bouwman"},{"key":"ref27","author":"Saha","year":"2025","journal-title":"Expert Insights into Advanced Persistent Threats: Analysis, Attribution, and Challenges"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-57878-7_14"},{"key":"ref29","first-page":"851","article-title":"Reading the tea leaves: A comparative analysis of threat intelligence","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Li"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616581"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3342112"},{"key":"ref32","volume-title":"Evaluating Threat Intelligence Feeds FIRST Technical Colloquium for Threat Intelligence","author":"Kompanek","year":"2016"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00490-y"},{"key":"ref34","article-title":"The Case for Scale in Cyber Security","volume-title":"0100","author":"Iozzo","year":"2025"},{"key":"ref35","first-page":"2783","article-title":"99% false positives: A qualitative study of SOC analysts\u2019 perspectives on security alarms","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Alahmadi"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/BigData59044.2023.10386664"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CSR57506.2023.10224937"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825640"},{"issue":"0704","key":"ref39","first-page":"1","article-title":"The diamond model of intrusion analysis","volume":"298","author":"Caltagirone","year":"2013","journal-title":"Threat Connect"},{"key":"ref40","article-title":"Big game hunting: The peculiarities in nation-state malware research","volume-title":"Black Hat","author":"Marquis-Boire","year":"2015"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/DSC61021.2023.10354155"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1080\/23742917.2021.1895532"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3175719"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68612-7_11"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/QRS54544.2021.00018"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-80825-9_7"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678909"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1093\/isp\/ekae022"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2010.03.003"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1142\/s2377740022500026"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3653973"},{"key":"ref52","volume-title":"Apt-mmf: An advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion","author":"Xiao","year":"2024"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484759"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3176674"},{"key":"ref55","first-page":"543","article-title":"A look at targeted attacks through the lense of an ngo","volume-title":"Proceedings of the 23rd USENIX Conference on Security Symposium, ser. SEC\u201914","author":"Le Blond"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1111\/risa.13732"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00047"},{"key":"ref58","volume-title":"DebUNCing Attribution: How Mandiant Tracks Uncategorized Threat Actors | Mandiant","author":"Vanderlee","year":"2025"},{"key":"ref59","article-title":"Understanding Threat Actor Naming Conventions","volume-title":"Infosecurity Europe","author":"Poireault","year":"2025"},{"key":"ref60","article-title":"Tracking unc2452-related reporting","volume-title":"MITRE","year":"2025"},{"key":"ref61","volume-title":"Threat Actor - MISP galaxy","author":"Dulaunoy","year":"2025"},{"issue":"06","key":"ref62","first-page":"36Z","volume":"T06","author":"Cristaldi","year":"2025","journal-title":"APTMap"},{"key":"ref63","volume-title":"The Newcomer\u2019s Guide to Cyber Threat Actor Naming","author":"Roth","year":"2018"},{"key":"ref64","article-title":"All groups - Threat Group Cards: A Threat Actor Encyclopedia","volume-title":"Thai CERT","year":"2025"},{"key":"ref65","volume-title":"All Threat Actors, APTs and Known Groups","author":"Identity","year":"2025"},{"issue":"11","key":"ref66","first-page":"17Z","volume":"T04","year":"2025","journal-title":"RedDrip7\/APT_digital_weapon"},{"key":"ref67","volume-title":"Targeted cyberattacks logbook","author":"Securelist"},{"key":"ref68","volume-title":"How Microsoft names threat actors - Unified security operations"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-08509-8_7"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25560-1_10"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1080\/08850607.2020.1783877"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1177\/00223433231220264"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-42051-2_15"},{"key":"ref74","article-title":"Malpedia - actors","volume-title":"Malpedia","year":"2025"},{"key":"ref75","volume-title":"Feed misp threat actors - cortex xsoar integration","author":"Networks","year":"2025"},{"key":"ref76","volume-title":"MISP Galaxy with Various Threat Intelligence Producers","year":"2025"},{"key":"ref77","article-title":"Find an assured cyber incident response provider","volume-title":"NCSC UK","year":"2025"},{"key":"ref78","article-title":"Best security threat intelligence products and services reviews 2025 - gartner peer insights","volume-title":"Gartner","year":"2025"},{"issue":"2012","key":"ref79","first-page":"1","article-title":"Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (stix)","volume":"11","author":"Barnum","year":"2012","journal-title":"MITRE Corporation"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/2994539.2994542"},{"key":"ref81","article-title":"misp-galaxy\/clusters\/threatactor.json at main","volume-title":"MISP\/misp-galaxy","year":"2025"},{"key":"ref82","volume-title":"Computing Krippendorff\u2019s Alpha-Reliability","author":"Krippendorff","year":"2011"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1016\/j.mex.2023.102545"},{"key":"ref84","volume-title":"Virustotal - upload and analyse files and urls for free","year":"2025"},{"key":"ref85","volume-title":"CrowdStrike and Microsoft Unite to Deconflict Cyber Threat Attribution","author":"Meyers","year":"2025"},{"key":"ref86","volume-title":"The Value Of Threat Intelligence: The Second Annual Study Of North American & United Kingdom Companies","author":"Institute","year":"2018"},{"key":"ref87","volume-title":"Weaponization Techniques for Red Team Operations","author":"Bughra","year":"2025"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00047"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471858"},{"key":"ref90","article-title":"The Free Rider Problem","volume-title":"The Stanford Encyclopedia of Philosophy","author":"Cullity","year":"2025"},{"key":"ref91","volume-title":"Cooperative attack and defense in distributed networks","author":"Moore","year":"2008"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.52"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573548.pdf?arnumber=11573548","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:25:59Z","timestamp":1782969959000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573548\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":92,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00215","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}