bellingcat.com
Report: https://www.bellingcat.com/app/uploads/2015/10/MH17-The-Open-Source-Evidence-EN.pdf
38 tools in this domain.
Report: https://www.bellingcat.com/app/uploads/2015/10/MH17-The-Open-Source-Evidence-EN.pdf
Three-year update: https://www.bellingcat.com/news/europe/2017/07/17/mh17-open-source-investigation-three-years-later/
https://www.bellingcat.com/news/europe/2018/10/09/full-report-skripal-poisoning-suspect-dr-alexander-mishkin-hero-russia/
https://www.bellingcat.com/news/2020/12/14/fsb-team-of-chemical-weapon-experts-implicated-in-alexey-navalny-novichok-poisoning/
Methodology: https://www.bellingcat.com/resources/2020/12/14/navalny-fsb-methodology/
https://www.bellingcat.com/news/2022/02/27/follow-the-russia-ukraine-monitor-map/
Bellingcat Online Investigation Toolkit (https://bellingcat.gitbook.io/toolkit)
1. SolarWinds / UNC2452 → APT29 (2020-2021). https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29
2. M-Trends 2025 annual report — Mandiant tracked 302 different threat groups in 2024. PDF: https://services.google.com/fh/files/misc/m-trends-2025-en.pdf
3. APT groups catalogue: https://cloud.google.com/security/resources/insights/apt-groups
4. Trade-Offs of Cyber Attribution (methodology paper): https://cloud.google.com/blog/topics/threat-intelligence/trade-offs-attribution
5. Apply the Suspected/Possible confidence scale. Analysts score overlaps as Possible Association (weak) or Suspected Association (strong). https://gtidocs.virustotal.com/docs/suspected-attribution
2. Fancy Bear Ukrainian artillery (2016). https://www.crowdstrike.com/blog/bears-midst-intrusion-disclosure/
3. Global Threat Report (annual). https://www.crowdstrike.com/en-us/global-threat-report/
10. Adversary Universe — public web page documenting all tracked adversaries. https://www.crowdstrike.com/en-us/adversaries/
Naming complexity — same actor = FANCY BEAR / APT28 / Forest Blizzard / Strontium / Sofacy / Pawn Storm / Sednit. The 2025 Microsoft-CrowdStrike shared glossary (https://www.crowdstrike.com/blog/crowdstrike-microsoft-naming-glossary/) is an attempt to harmonise.
1. Insikt Group research portal — https://www.recordedfuture.com/research
4. Microsoft Digital Defense Report 2024 — https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report-2024
11. Update threat actor encyclopedia — https://learn.microsoft.com/en-us/defender/threat-intelligence/.
1. Cisco Talos 2025 Year in Review — https://blog.talosintelligence.com/
1. Stuxnet (2010) — analysis of the first cyber-physical weapon. https://securelist.com/stuxnet-and-zero-days/36407/
2. Flame (2012) — discovery of a sophisticated espionage toolkit. https://securelist.com/flame-mystery-auto-update-component/33051/
3. Gauss (2012) — discovery of nation-state banking malware. https://securelist.com/gauss-nation-state-cyber-espionage-banking-trojan/36620/
4. Equation Group (2015) — Q&A PDF documenting the most sophisticated APT group yet discovered. https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07205555/Equation_group_questions_and_answers.pdf
US bans (2017 + 2024): DHS banned Kaspersky products from US federal networks in 2017 (BND 2017-138). BIS (Bureau of Industry and Security) extended the ban to all US consumer and commercial sales in 2024. URL: https://www.bis.doc.gov/index.php/documents/bis-newsroom/press-releases/2024-kaspersky-lab-final-determination-62624/file.
Kaspersky's denial: Company has consistently denied improper ties to Russian intelligence. NPR interview: https://www.npr.org/2024/06/20/nx-s1-5013739/biden-administration-bans-kaspersky-lab-antivirus-software-citing-russian-ties
Global Transparency Initiative (GTI): Kaspersky launched the GTI in 2018 to address trust concerns: moved data processing to Zurich (2018), opened Transparency Centers in multiple countries (https://gti.kaspersky.com). URL: https://www.kaspersky.com/transparency-center