>
As I understand it, signifiers included command and control servers known to be under Russian state control.If you could be more specific, we could address this. However, you cannot, because the allegations are all this vague. If it's the assertion that I think it is, the "command and control servers" were asserted by Crowdstrike to be under Russian control, and its evidence for this, again, were somewhere deep in a rabbit warren of cross- and circular references[1].
> Do you work in this field? I've basically only seen lay people suggest this.
I have seen journalists claim that only lay people suggest this.
To your vague and amorphous allegations of "state actors", I reply with this specific analysis of the few concrete indicators of compromise supplied by the departments of the government making the allegation. It's farcical. If Russiagate were to be true, the Russian hackers are no better than script kiddies, using outdated PHP malware as they do. https://www.wordfence.com/blog/2016/12/russia-malware-ip-hac...
[1] Furthermore, IP addresses change constantly. Again, if you're referring to the assertion I think you are, that IP address had been defunct for over 2 years before the attack See https://www.wordfence.com/blog/2017/01/election-hack-faq/
An IP that was being used by Russian Intelligence today to hack a target may be used by another attacker to hack a different target a few days later. This can happen for several reasons:
- A hacked IP can be used by one attacker and then be compromised by a different attacker later on to also launch attacks.
- IP addresses change ownership from time to time. A Linode IP may be hacked by Russia and used to launch attacks. Then it may be shut down by Linode, change ownership and the new owner’s site can get hacked. Then that IP address is attacking once again, but the attacker is someone else.
- IP addresses are also dynamic if they belong to an internet service provider (ISP). Some of the IP’s in the Grizzly Steppe report do belong to ISP’s. For example we can see IP’s belonging to Yota.ru, a Russian internet service provider. The hostnames are ‘wimax-client.yota.ru’ which suggests that they are wifi customers. These IP’s are probably dynamic and regularly change hands. They may be used by one attacker today and a different attacker tomorrow.