← Latest papers
💻 computer science

Synthetic APTs: the Collapse of TTP-Based Attribution

This paper argues that AI-driven adversary emulation demonstrates how the ability of agents to dynamically adapt and weaponize defensive tools undermines the traditional reliance on static Tactics, Techniques, and Procedures (TTPs) for attributing cyberattacks to specific threat actors, effectively collapsing the barrier for individuals to operate with nation-state-level capabilities.

Original authors: Francesco Balassone, Víctor Mayoral-Vilches, María Sanz-Gómez, Paul Zabalegui-Landa, Stefan Rass, Davide Quarta, Daniel Sanchez-Prieto, Marina Oteiza-Álvarez, Almerindo Graziano, Lauren Min Kim, MinSe
Published 2026-06-08
📖 6 min read🧠 Deep dive

Original authors: Francesco Balassone, Víctor Mayoral-Vilches, María Sanz-Gómez, Paul Zabalegui-Landa, Stefan Rass, Davide Quarta, Daniel Sanchez-Prieto, Marina Oteiza-Álvarez, Almerindo Graziano, Lauren Min Kim, MinSeok Choi

Original paper dedicated to the public domain under CC0 1.0 (http://creativecommons.org/publicdomain/zero/1.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Idea: The "Digital Mask" Problem

Imagine you are a detective trying to catch a thief. In the past, you could identify the thief by their signature: maybe they always used a red crowbar, always picked locks from the left side, and always left a specific type of mud on the floor. In the cyber world, these signatures are called TTPs (Tactics, Techniques, and Procedures). If you see a hacker using "Red Crowbar #41," you know it's "Group A."

This paper argues that Artificial Intelligence (AI) is about to break this system.

The researchers built a digital playground (a "cyber range") and programmed AI agents to act like five different famous hacker groups (like APT28, APT29, Lazarus, etc.). They then watched these AI hackers fight against AI defenders.

The Shocking Result: Even though the AI agents were told to act like different groups, they all started the attack in the exact same way. They used the same tools, the same scanning methods, and the same entry points. It was as if five different people, wearing different masks, all walked into a bank through the exact same back door, using the exact same key, and left the exact same footprint.

Because they all looked the same at the start, a human detective (or a computer) can no longer say, "Oh, this is definitely Group A." The "fingerprint" has been blurred.


The Experiment: A Digital "Wargame"

The researchers set up two different "battlefields" to test this:

  1. The "Office Building" (Enterprise Network): A standard corporate network with 20 computers. It was relatively open, like a building with unlocked side doors.
  2. The "Fortress" (Military Infrastructure): A highly secure network with two separate organizations, heavy firewalls, and strict security zones. It was like a fortress with multiple layers of gates.

They ran 20 battles in total. In each battle, an AI attacker (pretending to be one of the 5 hacker groups) tried to break in, while an AI defender tried to stop them.

The Results: A Perfect Split

The outcome was incredibly predictable, regardless of which "hacker group" the AI was pretending to be:

  • In the Office Building: The AI attackers always won. They broke in and took over computers (between 2 and 12 of them).
  • In the Fortress: The AI defenders always won (or the fight ended in a tie). The attackers couldn't get past the front gate.

The Lesson: It didn't matter if the AI was pretending to be a Russian spy, a North Korean thief, or a Chinese hacker. The layout of the building (the network design) mattered far more than the "personality" of the attacker. If the doors were weak, the AI broke in. If the walls were strong, the AI failed.


The "Magic Trick" That Broke Attribution

The most interesting part of the study happened inside the "Office Building" battles.

The researchers expected the AI pretending to be "Group A" to use "Group A's" special tools, and "Group B" to use "Group B's" tools. Instead, all the AI attackers discovered the same trick independently.

They found that the defenders had left a management tool (called Velociraptor) sitting around with a default password.

  • The AI attackers didn't just hack the computers; they hijacked the defender's own security tool.
  • They turned the defender's security camera into their own remote control (Command and Control).
  • They used this trusted tool to move around the network, invisible to other security alarms.

The Analogy: Imagine a burglar breaking into a house. Instead of picking the lock, they find the homeowner's spare key hidden under the mat. Even worse, they find the homeowner's security system manual, use the homeowner's own security code to unlock the front door, and then use the homeowner's own security camera to watch the police arrive.

Why this matters: This trick wasn't in any of the "playbooks" for the specific hacker groups. It was a new, shared behavior that all the AI agents invented on their own because they were using the same underlying AI brain. Since they all did the exact same thing, you couldn't tell which "group" was responsible.


The Three Main Takeaways

  1. The "Start" is the Same for Everyone:
    When AI agents start an attack, they all do the same basic things first (scanning the network, guessing passwords). They only start acting differently later in the attack, if they get deep enough inside. But by then, they've already left a generic fingerprint that looks like everyone else's.

  2. The "Fingerprint" is Fading:
    In the past, if you saw a specific hacking technique, you could say, "This is definitely the Lazarus Group." Now, if you see that technique, you can't be sure. It could be the Lazarus Group, or it could be a different group using an AI that just figured out that's the best way to do it. The "signature" is no longer unique.

  3. The Building Matters More Than the Burglar:
    The study found that the network design (how the computers are connected and protected) was the only thing that determined who won.

    • If the network was weak (Office), the AI won every time, no matter how "smart" the defender was.
    • If the network was strong (Fortress), the AI lost every time, even if the attacker was using the most powerful AI model available.
    • Key Insight: A smaller, cheaper AI defender could do just as good a job as a massive, expensive one, if the network was built securely.

Conclusion: What Does This Mean?

The paper concludes that we are entering an era where attribution is broken.

In the past, we could identify a cyber-attacker by their "style." Now, because AI can be programmed to act like anyone, and because AI tends to find the same "best" solutions to problems, different attackers will start looking identical.

If a bad actor wants to frame another country for a cyberattack, they can simply tell an AI to "act like Group X." The AI will likely produce the exact same "fingerprint" as the real Group X, making it impossible to tell who is really behind the attack.

The paper's final warning: We can no longer rely on "style" to catch cybercriminals. We must rely on stronger network walls (segmentation) and better security hygiene (like changing default passwords), because the "digital fingerprints" are no longer reliable.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →