Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The Attribution Story of WhisperGate: An Academic Perspective
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering. (SERL)ORCID iD: 0000-0002-0120-5388
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.ORCID iD: 0000-0002-9328-9143
2025 (English)In: Proceedings of the 35th Virus Bulletin International Conference, Virus Bulletin Limited , 2025, p. 107-118Conference paper, Published paper (Refereed)
Abstract [en]

This paper explores the challenges of cyberattack attribution, specifically APTs, applying the case study approach for the WhisperGate cyber operation of January 2022 executed by the Russian military intelligence service (GRU) and targeting Ukrainian government entities. The study provides a detailed review of the threat actor identifiers and taxonomies used by leading cybersecurity vendors, focusing on the evolving attribution from Microsoft, ESET, and CrowdStrike researchers. Once the attribution to Ember Bear (GRU Unit 29155) is established through technical and intelligence reports, we use both traditional machine learning classifiers and a large language model (ChatGPT) to analyze the indicators of compromise (IoCs), tactics, and techniques to statistically and semantically attribute the WhisperGate attack. Our findings reveal overlapping indicators with the Sandworm group (GRU Unit 74455) but also strong evidence pointing to Ember Bear, especially when the LLM is fine-tuned or contextually augmented with additional intelligence. Thus, showing how AI/GenAI with proper fine-tuning are capable of solving the attribution challenge.

Place, publisher, year, edition, pages
Virus Bulletin Limited , 2025. p. 107-118
Keywords [en]
AI, cybersecurity
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:bth-28800OAI: oai:DiVA.org:bth-28800DiVA, id: diva2:2008013
Conference
35th Virus Bulletin International Conference, Berlin, Sept 24-26, 2025
Available from: 2025-10-21 Created: 2025-10-21 Last updated: 2025-10-27Bibliographically approved

Open Access in DiVA

fulltext(875 kB)54 downloads
File information
File name FULLTEXT01.pdfFile size 875 kBChecksum SHA-512
ec2ce1d0f3260aea3a92b73196ff1309ca1bb20c9723a9a3933531e487ec1ec33c37ab596e7d45b9ecba41a446b18e9d87421d5bbf4b36f536c015d3b5bbb4c0
Type fulltextMimetype application/pdf

Authority records

Adamov, OleksandrCarlsson, Anders

Search in DiVA

By author/editor
Adamov, OleksandrCarlsson, Anders
By organisation
Department of Software EngineeringDepartment of Computer Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 1138 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf