skip to content

How does an untargeted infostealer infection become a targeted intrusion months later?

level: middleimportance: should knowfreq 46%

answer

  1. two actors, two different units of payment
  2. who chooses the victim, and when
  3. what makes a pile of bundles searchable
  4. the saved-address list is the price tag
  5. selection happens at purchase, not at infection

basics

~20 s

Through resale. The operator spreads the build indiscriminately and sells the bundles in volume; a buyer later searches that catalogue for a corporate address and pays for the one that reaches a chosen company. Targeting happens after the theft.

solid answer

~50 s

There are two actors with two different economics in this chain. The operator is paid per install and is indifferent to whose machine it is - the product is volume, so the lure is whatever gets executed most: cracked software, game mods, fake installers. The buyer's economics are the reverse: they pay per bundle and want one specific thing, so their selection criterion is what the bundle's fingerprint shows - the hostname, and above all the list of saved and visited addresses, which is what makes bundles searchable by company. A bundle whose address list contains a corporate portal is worth many multiples of one that contains only consumer sites. The consequence people get wrong is the claim `nobody targeted us`. Nobody targeted you at infection time. You were selected afterwards, out of a catalogue, by someone who was not present when the machine was infected and who may be the second or third owner of that bundle.

go deeper

for a junior

Know that the person who infects the machine and the person who uses the result are usually different people, and that a bundle is bought from a catalogue rather than aimed at anyone.

for a middle

Explain the two economics side by side - paid per install versus paid per bundle - and identify the fingerprint's saved-address list as the selection surface that turns volume into targeting.

for a senior

Demonstrate that you reason about contents rather than sophistication: what the profile held and what would still be accepted, not how the malware was packed or how long it ran.

for a principal

Be able to argue to a business audience that indiscriminate infection and targeted use are compatible, so third-party and personal-device access cannot be scoped on the assumption that nobody is interested in them.

## Two actors, two prices The thing that makes this chain hard to reason about is that the person who steals the material and the person who uses it against you are usually different people, with incompatible objectives, separated by months. **The operator and their customers** run a subscription product and are paid per install. They do not choose victims; they choose lures with the widest reach - cracked applications, key generators, game mods and cheats, fake updates. Their output is a large pile of undifferentiated bundles. Their skill is distribution, not intrusion. **The buyer** is at the other end. They want access to one company, or to any company of a certain kind, and they are shopping. They pay per bundle, and their whole problem is selection: which of a very large catalogue reaches somewhere worth the price. ## The fingerprint is the price tag Every bundle ships with an automatically generated description of the machine it came from: hostname, username, locale and rough location, installed software, and - the decisive field - the **list of addresses the profile had saved or visited**. That list is what makes an undifferentiated pile searchable. A buyer does not read bundles; they query the catalogue for a domain. So price is driven by reach, not by size: - a bundle whose addresses are all consumer services is near-worthless and sells in bulk lots; - a bundle containing a corporate single-sign-on portal, a remote-access address, a code host or an administrative console is priced individually and can be worth orders of magnitude more; - the same bundle can be sold **more than once**, and re-listed by its buyer afterwards, so the number of parties holding a copy only ever grows. This is why a contractor's own laptop, used for one browser tab of corporate work and infected through a game mod, is a serious event even though nothing about the infection was aimed at you. The machine was never targeted. **The bundle was.** ## The interval, and who sets it Because selection happens after the theft, the gap between infection and first hostile use is set by the market, not by the operator. It is a function of when the bundle was listed, when it was searched for, and whether the buyer had a use for that particular company at that moment. That interval is routinely months and can be years. There is no decay function you can apply to it - a bundle sitting unsold is not aging out, it is inventory. ## The classification error to avoid The error is symmetrical and both halves are wrong: 1. *We were not targeted, so this is low severity.* You were not targeted at infection. You may be targeted at purchase, which is the moment that matters. 2. *Corporate material was taken, so a sophisticated adversary is after us.* Not implied either. A per-install operator will hoover up a defence contractor and a teenager with equal enthusiasm because they never looked. Capability of the eventual buyer is not inferable from the infection. The honest statement is that the infection was indiscriminate and the use is discretionary, and only the second one tells you anything about who is interested in you. ## Why this shapes the response If targeting happens at purchase, then the questions worth asking are about the **contents** of what left, not about the sophistication of what landed. What addresses were in that profile? Which of those, once presented by someone else, would still be accepted? Which of them are held by a person whose machine you cannot see? Everything about the malware itself - how it was packed, how it was delivered, how long it ran - is subordinate to the inventory question, because the malware is a commodity and the inventory is the product. ## Answering it in a loop Name the two actors and their two units of payment. Say that the fingerprint's address list is the selection surface and the price driver. Then land the corrective: indiscriminate infection and targeted use are compatible, they are just separated by a market and several months, and the second party may not be the last one to hold a copy.

  • Does a bundle stop being valuable once it has been sold once?
    No. A bundle is data, so selling it does not remove it from the seller, and the buyer can re-list it. The realistic assumption is that the number of parties holding a copy only grows over time, which is why the first hostile use is not necessarily the last.
  • Can you infer the eventual buyer's capability from how the machine was infected?
    No, and this is a common error. Delivery was chosen for volume, not for you, so it says nothing about who buys the result. A crude cracked-software lure can end with a capable, well-funded buyer who never wrote a line of the malware.
  • Why is the fingerprint's address list more valuable to a buyer than the archive's raw size?
    Because the buyer's problem is selection, not quantity. Size tells them how much a stranger browsed; the address list tells them which organisations that machine could reach, which is the only thing that determines whether the bundle is worth buying at all.

The thief empties every unlocked car on the street and sells the contents by the crate. Someone else buys a crate because the catalogue said one of the door passes opens your building.

saying these in an interview costs you the question

  • Nobody targeted us, so this is low severity
  • Corporate data taken means a sophisticated adversary
  • The operator chose this machine deliberately
  • Once sold, only one party holds the copy
  • An unsold bundle loses value over time

context