Two Actors Changed Method This Year and Both Invalidated the Lesson Their Last Attack Taught. Demonstrated Evolution Is the Only Actor Claim You Can Actually Check.
- Patrick Duggan
- 1 day ago
- 5 min read
Updated: 4 hours ago
Almost everything written about threat actors is adjectives. Sophisticated. Advanced. Highly capable. None of it is checkable. You cannot falsify "sophisticated," which means you cannot be wrong about it, which means it carries no information.
There is one actor claim that is checkable: demonstrated evolution. Two dated observations of the same named actor operating at measurably different tiers. Nobody has to take your word for it, because both endpoints are public and both have dates on them.
We got two this year. They point in opposite directions, and that is the interesting part.
Case one: CyberAv3ngers climbed
November 2023. The Municipal Water Authority of Aliquippa, Pennsylvania. CyberAv3ngers took over a Unitronics Vision PLC. The technique was the default password. It was 1111.
That is not an exploit. It is an unlocked door. The security community read it accordingly — a politically-branded crew with a banner and no craft.
2026. Tenable attributes to the same group exploitation of [CVE-2021-22681](https://analytics.dugganusa.com/api/v1/dredd/kev-gap?cve=CVE-2021-22681) against Rockwell Logix controllers. That is a CVSS 10.0 in which a shared cryptographic key, embedded in Studio 5000 Logix Designer, is the entire identity check between a controller and its engineering station. Extract the key and the controller accepts you as the engineer — logic, configuration, firmware.
Between those two points sits real work: understanding a vendor's authentication design, obtaining the key, and speaking the protocol well enough that an industrial controller believes you.
Same group. Three years. Unlocked door to cryptographic trust-model bypass.
Case two: ShinyHunters went the other way
2025. ShinyHunters compromised Salesloft's GitHub and pulled the OAuth tokens for the Drift integrations out of source. Those tokens authenticated directly into 700-plus Salesforce tenants.
The defining property of that attack is that the victims were never touched. Nobody was phoned, nothing was clicked, no credential was surrendered. The vendor was compromised and every customer inherited it.
2026. Brinks Home confirms a breach; ShinyHunters claims 4.9 million Salesforce records. Health-ISAC separately warns members about the same crew hitting healthcare. Both describe the same method, and it is not the one above.
They are making phone calls. Voice social engineering against help desks, into Microsoft Entra SSO.
Measured on technical difficulty that is a step down. Extracting OAuth tokens from a compromised source repository is harder than persuading a service desk to reset an MFA factor.
Measured on results it is a step up, because it works, and because it routes around every control the previous attack taught people to build.
The thing both cases have in common
Each new method invalidated the defensive lesson the previous one taught.
Aliquippa taught the water sector: change your default passwords. Correct, necessary, and insufficient against the same actor three years later. A utility that did exactly what Aliquippa told it to do is not protected against a Logix trust-model bypass. Nothing about a strong password stops an attacker who is holding the key that proves he is the engineer.
Salesloft taught enterprises: audit your OAuth integrations, know what your vendors can reach, treat an installed app as a standing credential. Correct, necessary, and insufficient against the same actor a year later. An organisation that inventoried every OAuth grant is not protected against someone phoning the help desk.
That is the finding, and it is uncomfortable because it cuts against how the industry learns. We turn incidents into lessons. Lessons become checklists. Checklists become audits. And the whole pipeline is calibrated to the last thing an actor did.
The shelf life of a defensive lesson is set by the adversary, not the defender. Both of these actors demonstrated that they will change method faster than a compliance cycle can absorb the previous one.
Evolution is not a ladder
If you only had CyberAv3ngers you would conclude that actors get more sophisticated over time, and you would build a threat model that escalates in one direction.
ShinyHunters shows that is wrong. They abandoned a technically superior attack for a technically trivial one, because the trivial one had a better yield. Adversaries are not climbing a ladder toward sophistication. They are doing whatever currently works, and technical elegance is not a factor except where it improves the return.
This matters for how you read vendor reporting. "Increasingly sophisticated" is a common phrase and is frequently the opposite of what the evidence shows. An actor that moves from supply-chain exploitation to phone calls has not regressed. It has optimised. If your threat model only escalates, you will be looking up while they walk in the side door.
The corollary is not comfortable either: a low-sophistication observation tells you nothing about ceiling. The 2023 read on CyberAv3ngers — default passwords, therefore unserious — was a reasonable inference from the evidence and it aged into a liability. The people who dismissed them are exactly the ones who did not revisit their assumptions in time.
What this means operationally
Date every capability claim you hold about an actor. "CyberAv3ngers uses default credentials" was true in 2023 and is now a stale fact presented as a current one. An undated capability claim silently becomes wrong.
Treat your last incident lesson as perishable. Not wrong — perishable. Keep doing it, and separately ask what it does not cover.
Watch for method change specifically, not just new indicators. A new IP from a known actor is routine. A known actor arriving through a completely different door is a different class of event and should trigger a threat-model review, not a blocklist update.
And stop scoring actors on sophistication. Score them on demonstrated change: what did they do, when, and is it different from last time. That is checkable. Sophistication is not.
What we cannot do yet, including on our own data
We should be able to compute this across every actor we track. We cannot, and the reason is our own.
Our adversary index holds 400 profiles. Twenty-one of them have both our own published coverage and some structured capability data. Of those twenty-one, `cves_exploited` is populated on two, and `first_seen` on four. The fields that would let us diff an actor's capability between two dates are mostly empty.
The raw material is there — 79 published posts on ShinyHunters, 15 on CyberAv3ngers, all dated. The corpus is a longitudinal record of exactly this. But it has to be read by hand, which means we notice evolution when it is dramatic enough to be obvious, and miss it when it is gradual. That is the wrong failure mode for the one actor claim that is actually falsifiable.
So this post is two cases, not a dataset. Fixing the structured fields so the next one can be a dataset is now on our list.
What we are not claiming
The CyberAv3ngers CVE attribution is Tenable's, made on operational-pattern grounds. The ShinyHunters vishing shift is described by Brinks Home's disclosure and Health-ISAC's advisory, not by us. The Salesloft/Drift chain was documented by multiple vendors before we wrote about it. None of these observations are ours.
What is ours is the pairing — noticing that two of the actors we track longest both changed method inside twelve months, in opposite technical directions, and that both changes broke the lesson their previous attack had taught. That is a corpus observation, which is the thing a long archive is for.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
