False Flag
Definition
A deliberate deception in which an attacker plants indicators designed to make the intrusion appear to originate from a different actor. Common techniques include reusing another group's known malware, inserting foreign-language strings, or routing traffic through infrastructure associated with a different threat actor.
- Context
- Cyber attribution investigations
- Goal
- Make an intrusion appear to originate from a different actor
- Common technique 1
- Reusing another group's known malware
- Common technique 2
- Inserting foreign-language strings or false linguistic cues
- Common technique 3
- Routing traffic through infrastructure tied to a different actor
Common questions
Why does false-flag activity make attribution so difficult in cyber investigations?+
Attribution normally relies on technical indicators like malware code reuse, infrastructure overlap, and language artifacts, and a capable attacker can deliberately plant exactly those indicators to point at a different group, so investigators must weight indicators by how easily each can be forged rather than trusting any single overlap.
How do investigators try to see past a false-flag operation?+
Analysts look for artifacts that are harder to fake convincingly, such as consistent operational tradecraft over time, infrastructure registration patterns, timing tied to a plausible actor's working hours or holidays, and corroborating intelligence outside the compromised network, rather than relying on any single planted clue.
Related terms
- Attribution
- The process of identifying the threat actor responsible for a cyberattack. Attribution is a confidence-weighted analytical conclusion, not a binary fact. It...
- Confidence Level
- An explicit label attached to an attribution assessment indicating how strongly the available evidence supports the conclusion. Standard tiers are low, medium,...
- Technical vs Legal Attribution
- Technical attribution identifies the infrastructure and tooling used in an attack and may link it to a known cluster or actor profile....
- Threat Actor Cluster
- A named collection of observed activity linked by shared infrastructure, malware, and TTPs, without necessarily having confirmed the real-world identity of the...
- TTPs (Tactics, Techniques, and Procedures)
- The behavioural fingerprint of a threat actor: the broad goals and approaches they pursue (tactics), the specific methods they use to achieve...