Skip to content

Tag: Nation-State Cyber Attacks

Tracking Adversary Infrastructure With Censys Data

Adversary infrastructure — the C2 servers, phishing kits, and malware staging behind every attack — can be mapped from a single clue using internet intelligence. This guide shows how researchers do it, with real published cases.

How Internet Intelligence Helps Investigate Cyber Attacks

Every cyber attack leaves infrastructure clues on the public internet. This guide explains how investigators pivot from one malicious indicator to an entire attacker network — and why attribution must never rest on a single clue.

Russia-Ukraine Cyber War: Tracking Digital Infrastructure

Cyber operations in the Russia-Ukraine war run on infrastructure — servers, certificates, domains, and compromised devices that leave traces on the public internet. This article explains the tracking methodology researchers use to find and monitor it, with documented cases from the FBI's Cyclops Blink disruption to CERT-UA's infrastructure investigations.

Israel-Iran Cyber War: What Internet Intelligence Shows

The Israel–Iran cyber war runs alongside the 2026 conflict — wiper attacks, exposed industrial controllers, and hacktivist DDoS waves. Here is what internet intelligence reveals about the digital front, and how researchers track it.

Censys, Iran Cyber Attacks and Exposed Infrastructure

U.S. agencies confirmed Iranian-affiliated hackers are exploiting internet-exposed PLCs in water, energy, and government sectors. Censys research measured the attack surface — 5,219 exposed controllers, most in the U.S. — and showed how scan data helps defenders fight back.

Cyber Warfare Research: Using Internet Scan Data (2026)

How threat-intelligence analysts use internet-wide scan data to study cyber warfare: certificate pivoting, infrastructure baselining, reuse tracking across threat reports, and the hard limits of what scan data can prove. Real case studies from Censys research and documented investigations.