>Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses."
Yes, a decent chunk of it comes down to that general idea, but in practice you're dealing with a ton of permutations of that idea. You don't want the adversary to know the specific data types or values you were pivoting off of and correlating against.
So it's not about the general methodology but the specific applications and indicators. Plus there are many other attribution methods beyond just that.
>I should assume their statement is false until evidence is provided. That's a fairly universal concept.
I don't think that's how that works. You just have no evidence or reason to believe their statement is true. That's different from assuming their statement is false. "Failing to reject the null hypothesis" isn't the same thing as "confirming the null hypothesis".
>https://www.crowdstrike.com/blog/two-birds-one-stone-panda/
>One past example of a "hacking group believed to have links to the Chinese government" was someone they suspected as a hacker taking an rideshare to a large office building that rented space to a government organization.
That seems like a major misrepresentation. Here're the two posts that that CrowdStrike post is based on:
https://intrusiontruth.wordpress.com/2018/08/02/who-is-mr-ga...
https://intrusiontruth.wordpress.com/2018/08/15/apt10-was-ma...
I'm not going to summarize everything IntrusionTruth and CrowdStrike reported, but it definitely wasn't just "someone they suspected as a hacker taking a rideshare to a large office building that rented space to a government organization". It was someone whose name and other personal information they already had likely associated with APT10 - through several different means - allegedly also appearing on multiple Uber ride receipts with a destination of the regional headquarters of the Ministry of State Security, which is in the city he appears to work and live in. (Among several other indicators pointing to his likely involvement, including potential associations between local companies he was affiliated with and the Ministry of State Security Tianjin Bureau + APT campaigns.)
What are you basing this "rented space to a government organization" on? Could you imagine the NSA putting a regional headquarters in some rented office space, for example?
In my opinion, the totality of the combined analyses makes a pretty good case that Gao was part of APT10, and a moderate case that he may have worked for or with the Ministry of State Security Tianjin Bureau. Combined with other reports published by both parties, the case for associations between APT10 and MSS Tianjin Bureau is additionally strengthened.
Then a few months later, the Justice Department announced this indictment: https://www.justice.gov/opa/pr/two-chinese-hackers-associate...
>Two Chinese Hackers Associated With the Ministry of State Security Charged with Global Computer Intrusion Campaigns Targeting Intellectual Property and Confidential Business Information
>Defendants Were Members of the APT 10 Hacking Group Who Acted in Association with the Tianjin State Security Bureau and Engaged in Global Computer Intrusions for More Than a Decade, Continuing into 2018, Including Thefts from Managed Service Providers and More Than 45 Technology Companies