>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…
An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.
Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry.
Give me a reason to trust them again?