In Defense of the Dark Arts: Operationalizing Managed Attribution

The online realm is composed of countless pocket dimensions brimming with hidden risk.

Share
A shadowy figure hunches over a computer as if examining the internals of a hard drive while the shadow of a raven stands watch.
In Defense of the Dark Arts by Ravenwood

This is the part four of a five part tradecraft series on managed attribution strategies. Don't forget to check out parts onetwo, and three.


Now for the fun part! Up to this point, we’ve focused on managed attribution as defense. We’ve set the ground rules, confronted the unseen obstacles of passive browsing, and navigated the minefields of third-party data sources. For some organizations, that’s enough. If that’s you, congratulations! Go forth and prosper. However, the online realm is composed of countless pocket dimensions brimming with hidden risk. In this article, we’ll explore what is required to safely evolve online operations from quiet observation to active collection in order to uncover the most challenging threats organizations face.

Fictitious Personas

Many of the most prominent social media platforms provide a Terms of Service clause regulating or outright prohibiting the use of pseudonyms on their platforms, even for law enforcement. A brief Google search will return a host of results detailing instances of civil and criminal proceedings involving the use of fictitious personas, frequently referred to as sock puppets. Some cases have succeeded where others have failed, but for many, the mere potential for legal jeopardy is enough to swear off this level of effort.

To the extent DOJ guidance from 2020 still carries weight, the Computer Crime & Intellectual Property Section's Cybersecurity Unit previously highlighted some Legal Considerations when Gathering Online Cyber Threat Intelligence and Purchasing Data from Illicit Sources. The document doesn't address the use of fictitious personas on mainstream social media platforms but does lean favorably toward their use within strict ethical frameworks. It also goes on to discuss more intrusive measures and is worth committing to memory and discussing with in-house counsel.

Prior to resorting to the use of fictitious personas, organizations should establish rules of engagement (RoEs), including clear boundaries that shall not be crossed. Personas should be broken down into at least two different categories, with the potential for further segmentation in the future. In this section, we'll focus on personas with minimal engagement. These accounts exist primarily to gain access to forums and websites that require a valid account for consumption.

In most cases, these types of accounts are not actively approved or denied by an administrator. The limitation often exists solely to deter responsible web crawlers and search engines from indexing private data. In addition to the legal risks discussed above, a researcher should also consider whether site owners, administrators, or moderators pose a threat. If you are establishing an account on a forum owned or operated by criminals, terrorists, or really petty trolls (you know the one), then the answer is yes. Accessing the site poses a threat.

In addition to the security measures necessary to manage attribution and legal considerations outlined by the Justice Department, you must also consider how your activity on the platform may be scrutinized by its administrators. Do they store logs? Do they implement ad tech? Can they read your messages? Do shared files retain metadata? All of these considerations and more should factor into your plan for how to operate a fictitious persona on the site, and what might be necessary to avoid correlating your account with other signatures that may allow the threat actor to perform attribution against you.

Online Operations

Implementing a framework for the use of fictitious accounts will quickly introduce new boundaries and questions for researchers in contested online spaces. While an organization may feel comfortable interacting with a bot to request a channel link or following a dangerous organization’s media outlet for up-to-date news, the bar for further engagement should be set high. Close legal scrutiny may reveal legally permissible ways to operate a fictitious persona on the dark web in pursuit of sensitive, high-value intelligence relevant to specific business needs.

⚠️
The information in this article is intended solely for legitimate information security and threat intelligence purposes. This does not constitute legal advice and confers no rights or remedies under the law. Minor factual changes can substantially alter the legal risks associated with interacting with illicit sources or forums. Readers are highly encouraged to consult with qualified legal counsel before implementing these strategies.

On the extreme end of online safety concerns, asking a paranoid supervillain to share their mass murder plans is not something to be taken lightly. Nor is doing it on a platform operated by hackers whose livelihood depends on protecting the privacy of supervillains. While exaggerated, this point is extremely important. Beyond adherence to established RoEs, this type of activity demands baseline knowledge, skills, and abilities which organizations should not undervalue. Detailed operational plans are necessary prior to execution and should be assessed through the lens of a red team to identify and mitigate potential vulnerabilities.

As risk and reward mount, so does complexity. At this stage, a risk matrix should include more than just tailored virtual environments to mitigate the physical and digital threats of an adversary. Organizations must consider how their actions influence adversaries, as well as their impact on unseen efforts (e.g., military, law enforcement, and/or intelligence services also interested in the threat actor). Researchers’ presence and activity may unwittingly attract the attention of criminal investigators and intelligence services. When poor tradecraft aggravates an adversary to the point of behavior modification, it could compromise sensitive accesses and disruption plans.

The views expressed in this article are solely those of the author and do not necessarily represent the views of the FBI, the DOJ, the United States government, or any past or current employers.