Researchers Reveal Innovative Approach to Trace Compartmentalized Threats

Researchers Reveal Innovative Approach to Trace Compartmentalized Threats

In May 2025, a joint team from Cisco Talos and The Vertex Project introduced a transformative strategy to address a new breed of cyber threats: distributed attacks involving multiple, loosely coordinated threat actors. These actors each handle separate parts of an intrusion, forming a complex and compartmentalized offensive.

This evolution from isolated attackers to collaborative adversary ecosystems has outpaced conventional cybersecurity tools, making it harder to trace, attribute, or contain breaches.

To counter this, the researchers unveiled a novel analytic framework that reimagines the traditional Diamond Model. By embedding a dynamic “Relationship Layer,” the framework uncovers hidden connections among attackers, infrastructure, tools, and targets—creating visibility across disjointed phases of an attack lifecycle. The model aims to illuminate the invisible networks behind today’s most elusive cyber operations.

Distributed Intrusion Ecosystems: Rethinking the Cyberattack Supply Chain
(Source: Cisco Talos)

Modern threat campaigns rarely follow a single thread. Increasingly, breaches originate from Initial Access Brokers (IABs) — threat groups that gain footholds in enterprise environments and auction off access to downstream actors. One such player, ToyMaker, operates with remarkable precision, providing an entry point for follow-on operators such as ransomware gangs or nation-state groups.

In one notable 2023 operation, ToyMaker infiltrated an organization using a bespoke backdoor known as LAGTOY, maintained persistence, harvested credentials, and later ceded control to the Cactus ransomware collective. This baton-passing structure fractures visibility, as defenders frequently assign blame based on the final payload, overlooking earlier intrusion phases entirely.

Research from Cisco Talos reveals that 67% of ransomware breaches in 2024 originated from IAB activity—a clear signal that traditional linear threat models are insufficient for mapping today’s distributed threat landscape.

“This isn’t just stealth; it’s structure,” explained Edmund Brumaghin, lead analyst at Cisco Talos. “Threat actors now operate like modular supply chains—delegating access, tooling, and execution. If defenders focus only on endpoints, they’ll miss the relationships that drive the campaign.”

Initial Breach Vector: Precision Phishing at Scale
ToyMaker exemplifies how IABs leverage tailored lures to seed attacks. Their campaigns typically begin with well-crafted spear-phishing emails that deliver weaponized ISO attachments disguised as routine invoices—opening the door to deeper exploitation and future handoffs.

Fragmented Intrusions, Unified Outcomes: Inside a Modern Attack Lifecycle
(Source: Cisco Talos)

Today’s most evasive cyberattacks are no longer single-threaded exploits. They unfold as carefully timed sequences of handovers between loosely affiliated actors. In one such campaign, access broker ToyMaker initiated compromise via malicious ISO attachments in spear-phishing emails. Once launched, these files executed a covert PowerShell script (deploy.ps1) designed to retrieve a secondary payload from a third-party-operated Traffic Distribution Service (TDS)—a tactic that fragments responsibility and complicates traceability.

The downloaded malware, LAGTOY, bypassed memory defenses using reflective DLL injection, then entrenched itself using a custom Windows Scheduled Task, obfuscated with base64-encoded commands:

LAGTOY established command-and-control through HTTPS channels, employing RC4 encryption with session-based keys, a tactic aimed at evading static detection rules. Credential theft followed—particularly PuTTY private key files (.ppk)—which were quietly staged for delivery to a ransomware-as-a-service (RaaS) partner: Cactus.

One of the most elusive aspects of this campaign was the intentional pause—a three-week dormancy window—during which ToyMaker erased operational traces before handing off control. Cactus then reentered the environment using the stolen credentials, launched network reconnaissance with tools like SoftPerfect Network Scanner, and deployed their ransomware payload.

Shared infrastructure, often hosted on bulletproof servers, further blurred attribution, as the same command nodes were reused across unrelated campaigns—breaking the assumption that shared indicators imply shared identity.


Why Attribution Fails—and How Relationship-Centric Models Fill the Gaps

Legacy detection models often collapse under the weight of such complexity. The attack chain isn’t broken; it’s outsourced.

The extended Diamond Model addresses this by mapping out transactional relationships between actors. Instead of forcing ToyMaker and Cactus into a single adversary profile, it labels their interaction as a brokered transfer—a meaningful distinction that preserves analytical clarity.

By identifying “handover,” “purchase,” or “shared use” as distinct relationship types, analysts can connect the dots between phases without conflating motivations, techniques, or attribution.

This isn’t just about threat detection—it’s about evolving how defenders understand the threat landscape: one relationship at a time.

From Signals to Syndicates: A New Lens on Intrusion Analysis
(Source: Cisco Talos)

Traditional threat detection often assumes linear timelines—but modern intrusions don’t play by those rules. Cisco Talos urges security teams to pivot toward asynchronous threat pattern recognition—where tactics like credential harvesting may precede lateral movement by weeks. These delayed maneuvers are often a sign of access being passed between actors.

To surface these invisible transitions, defenders should link early-stage indicators of compromise (IOCs)—such as known LAGTOY artifacts—with downstream ransomware intelligence. Talos researchers found that nearly 9 out of 10 victims targeted by Initial Access Brokers (IABs) experience follow-up exploitation within six weeks, underlining the urgency of proactive mapping.

This shift demands more than endpoint vigilance—it calls for a networked view of adversarial behavior. By treating intrusions as interconnected operations rather than isolated events, defenders can dismantle the relationships powering cybercrime alliances. It’s not just a change in tactics—it’s a redefinition of what it means to disrupt.

More Articles & Posts