Cyber threat intelligence relies heavily on tracking Advanced Persistent Threats (APTs) to defend against state-sponsored attacks and organized cybercrime.
However, assuming these adversary groups are static entities ignores the reality of modern cyber warfare. Operators rotate, malware evolves, and attack infrastructure changes constantly to evade detection.
This creates a “Ship of Theseus” paradox for security analysts if a threat group replaces its tools, members, and tactics entirely, is it still the same group? Relying solely on static identifiers, such as traditional Tactics, Techniques, and Procedures (TTPs), now introduces severe risks of misattribution.
Shifting To Campaign-Based Tracking
Instead of trying to force new attacks into historical APT profiles, modern intelligence focuses on discrete, observable campaigns.
A campaign is defined as a time-bound cluster of malicious activity featuring a specific objective, targeted infrastructure, and a clear execution flow.
By isolating these events, threat hunters can evaluate them objectively and identify overlaps that link separate operations over time.

This overlap model shifts the focus away from finding a perfect match and toward gathering multi-dimensional evidence.
To establish genuine continuity, analysts evaluate overlaps across several distinct behavioral and technical layers:
- Strategic and operational layers analyze alignment with broad geopolitical goals, consistent victimology, and operational timing, such as established working hours.
- Tactical and technical layers map shared initial access methods, custom malware evolution, encryption routines, and overlapping source code structures.
- Infrastructure and human layers track reused TLS certificates, identical domain naming conventions, operator language artifacts, and distinct security habits.

Building The Linkage Graph
This campaign-centric approach naturally operationalizes into a Campaign Linkage Graph. In this model, every node represents a distinct cyberattack campaign, complete with its own timeframe and objectives.
The lines, or edges, connecting these nodes represent the strength of the overlapping evidence.

Instead of demanding to know whether the same APT launched two attacks, analysts evaluate how closely the two campaigns are connected and through which specific dimensions.
Connections in this graph reflect varying degrees of confidence. Strong links indicate substantial overlap across independent layers, leaving little room for alternative explanations.
Medium links represent partial overlaps where some technical or strategic dimensions align, but more evidence is needed. Weak links capture tentative similarities that serve as early hypotheses.
According to Dark atlas research, this graphical model handles adversary evolution and fragmentation seamlessly.
If an active threat group completely updates its ransomware payload while maintaining its preferred command-and-control infrastructure, the new campaign branches off the old one, with a traceable connection.
Splinter groups or collaborations appear as branching and merging nodes. Over time, an APT group becomes less of a rigid, dictionary-defined entity and more of an emergent cluster of strongly interconnected campaigns.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.