Threat Chords: Tuning into Persistent Patterns in Adversary Behavior
Karthika (Threat Researcher · Adobe), Samhita Vempatti (Threat Researcher · Adobe)
BSidesSF 2026 · Day 1 · AMC Theatre 13
Overview
In a landscape increasingly defined by rapid cyberattacks and sophisticated adversaries, the BSides SF talk "Threat Chords: Tuning into Persistent Patterns in Adversary Behavior" by Adobe cybersecurity researchers Karthika and Samhita Vempatti offered a compelling argument for shifting focus in threat intelligence. The core premise, inspired by musical chords, is that while individual indicators of compromise (IOCs)—the "notes" of an attack—may change frequently, the underlying behavioral patterns and operational playbooks—the "chords"—remain remarkably consistent over time.

Key moments
- 0:00 Introduction and the 'Threat Chords' concept
- 0:50 Talk's 'Set List': Agenda and key topics
- 2:00 Evolution of intelligence: From battlefields to backdoors
- 3:45 Actionable CTI: Combining data and context
- 4:45 Key CTI terminology: IOCs, TTPs, Threat Actors
- 6:00 Critiquing the traditional, indicator-heavy CTI model
- 6:45 Why indicators fail: They're 'designed to burn'
Threat Chords: Tuning into Persistent Patterns in Adversary Behavior
Speakers: Karthika; Samhita Vempatti, Cybersecurity Researchers, Adobe
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=gShSiM0cw4E
Overview
In a landscape increasingly defined by rapid cyberattacks and sophisticated adversaries, the BSides SF talk "Threat Chords: Tuning into Persistent Patterns in Adversary Behavior" by Adobe cybersecurity researchers Karthika and Samhita Vempatti offered a compelling argument for shifting focus in threat intelligence. The core premise, inspired by musical chords, is that while individual indicators of compromise (IOCs)—the "notes" of an attack—may change frequently, the underlying behavioral patterns and operational playbooks—the "chords"—remain remarkably consistent over time.
This talk is a critical examination of the prevailing, often reactive, approach to cyber threat intelligence (CTI) that heavily relies on blocking ephemeral IOCs like IP addresses and domain names. Karthika and Samhita argue that this "bottom-heavy" strategy, while having some value, ultimately leaves organizations vulnerable as adversaries swiftly pivot. By dissecting real-world campaigns from prominent groups like Scattered Spider and Shiny Hunters, as well as the lesser-known Amos info stealer, the speakers illustrate how focusing on tactics, techniques, and procedures (TTPs) and broader behavioral sequences provides a more enduring and effective defense.
The presentation is particularly relevant for security operations center (SOC) analysts, threat intelligence teams, and security leadership grappling with the challenge of staying ahead of adaptive adversaries. It champions a proactive, analytical methodology that prioritizes understanding the "muscle memory" of attackers, enabling more resilient detection and response strategies that can withstand the inevitable rotation of atomic indicators.
Background
▶ Watch: Introduction and the 'Threat Chords' concept (0:00)
The concept of intelligence, as Karthika highlighted, is far from new. It originated in military and national security operations, dating back centuries, with the fundamental question remaining constant: "What is the enemy going to do next?" From battlefields and intercepted communications in 1945, intelligence has evolved significantly. Today, it's primarily derived from logs and telemetry, with adversaries ranging from nation-states to sophisticated criminal groups and even opportunistic teenagers capable of social engineering Fortune 500 companies. Campaigns, once slow and protracted like wars, now unfold in a matter of hours from initial access to data exfiltration, and the attack surface has shifted from physical territories to cloud identity providers. Despite these changes, the mission of predicting adversary actions endures.
Modern cyber threat intelligence (CTI), as defined by the speakers, is built upon two fundamental layers: data and context. Data encompasses raw logs, telemetry, and feeds—everything a Security Information and Event Management (SIEM) system ingests. While data reveals what has happened, it's often noisy and high-volume. Context is where the analysis occurs, interpreting the data to understand behaviors, assess normalcy, and discern intent. The fusion of data and context yields actionable intelligence, which can manifest as detection rules, prioritization strategies, or high-level strategic decisions. The key takeaway here is that "data tells you what happens, but context tells you what it means."
The prevailing CTI model, as described, typically involves collecting commercial and open-source feeds, enriching them with metadata (e.g., VirusTotal, Shodan), sharing them with stakeholder teams (detection, SOC, product), and then blocking the identified IOCs. While not entirely without merit, this model is fundamentally flawed due to its heavy reliance on indicators of compromise (IOCs). IOCs are detectable artifacts—IPs, hashes, domains—that signal malicious activity. However, these are "designed to burn." As illustrated by the IOC life cycle, once an attacker's domain is detected and shared, the community blocks it, and the attacker simply replaces it, having budgeted for this rotation.
This challenge is famously articulated by the Pyramid of Pain, a foundational framework in CTI. At the base of the pyramid are hash values and IP addresses, which attackers can change with minimal cost or effort. Moving up, domain names incur slightly more cost (registering new ones, though often automated). Higher still are network and host artifacts (e.g., malware delivery methods) and tools (e.g., specific RMM tools, exploit frameworks); changing these causes more disruption to an attacker's workflow. At the apex are TTPs—the behavioral patterns and "muscle memory" of an adversary. Targeting TTPs forces attackers to fundamentally alter their operational methodology, incurring the highest cost and making their campaigns less successful. The speakers emphasized that current CTI programs are "bottom-heavy," over-investing in complex platforms to manage atomic indicators, rather than focusing on the enduring "chords" at the top of the pyramid.
Key Findings
▶ Watch: Evolution of intelligence: From battlefields to backdoors (2:00)
The central and most significant finding presented is that adversary behaviors, or "threat chords," exhibit remarkable persistence even as the specific tools, infrastructure, and atomic indicators ("notes") they employ are constantly changed or "burned." This insight challenges the prevalent, reactive approach in cyber threat intelligence that often prioritizes the rapid blocking of individual IOCs.
The speakers demonstrated through two distinct real-world campaign analyses that shifting focus from ephemeral indicators to stable behavioral patterns yields more effective and sustainable defensive strategies. They highlighted:
- The Enduring Nature of Operational Playbooks: Despite changes in group labels or specific targets, the underlying sequence of actions, the "muscle memory" of how adversaries conduct their campaigns, remains largely consistent. For financially motivated groups like Scattered Spider and Shiny Hunters, the identity compromise chord (social engineering leading to SSO abuse) has been successfully played across numerous high-profile incidents over years because it works and is expensive for attackers to fundamentally alter.
- Infrastructure Categories Over Specific Instances: While domains and IP addresses rotate rapidly, the types of infrastructure and their associated metadata often persist. Examples include consistent fishing domain templates or strong preferences for specific TLS issuers and network anonymization techniques that mimic legitimate traffic. Monitoring these broader categories provides a more robust detection surface.
- Behavioral Patterns Beyond Malware: Many sophisticated attacks, particularly those involving social engineering and identity compromise, do not rely on traditional malware. Instead, they leverage legitimate functionalities and permissions, making sequence-based detection of behavioral chords (e.g., privilege expansion via SAS permissions) far more effective than looking for individual malicious files.
- The High Cost of Changing TTPs: Reinforcing the Pyramid of Pain, the talk underscored that forcing adversaries to alter their fundamental TTPs is the most impactful defensive action. This contrasts sharply with the low cost and ease with which attackers can rotate atomic indicators like hashes and IPs.
In essence, the key finding is a call to action for the cybersecurity community to "chase the chords, not the notes"—to invest in understanding and detecting the persistent patterns of adversary behavior to build more resilient and future-proof defenses.
Technical Deep Dive
▶ Watch: Actionable CTI: Combining data and context (3:45)
The speakers illustrated their "threat chords" concept through detailed breakdowns of two distinct adversary campaigns: the high-profile activities of Scattered Spider and Shiny Hunters, and a lower-profile Amos info stealer campaign targeting Mac OS.
Scattered Spider and Shiny Hunters: The Identity Compromise Chord
These two groups, initially distinct but now seemingly collaborating, represent a significant threat. Scattered Spider (also tracked as UNC3944, Octo Tempest) is a financially motivated intrusion cluster renowned for its sophisticated social engineering campaigns targeting large enterprises and SaaS platforms. Shiny Hunters specializes in data theft and extortion, known for its "pay and leak" model on dark web sites, often accepting breaches of major companies. Their joint operations highlight that while threat actor labels may change, their operational playbooks persist. Notable incidents include the 2023 MGM Resorts and Caesars Entertainment breaches, Snowflake customer data theft, and Salesforce campaigns.
The typical attack chain for this combined group demonstrates a consistent "chord" of operations:
- Reconnaissance (OSINT): Attackers conduct extensive OSINT on target employees and companies, gathering information from LinkedIn (name, title, manager, direct reports) and databases containing sensitive details like SSNs.
- Identity Access (Vishing/Help Desk Social Engineering): This is a critical and highly effective phase. Attackers impersonate target employees via vishing (voice phishing) calls to the company's help desk. Often, knowing just a name, manager, and position is sufficient to bypass authentication checks. The MGM breach, for instance, reportedly resulted from a 10-minute help desk call, leading to a $100 million incident. Crucially, Scattered Spider and Shiny Hunters have integrated AI for voice cloning and even deepfakes for video verification into this phase, making it even more potent.
- Identity Provider (IDP) Compromise: Following successful social engineering, the attackers target the organization's identity provider (IDP), frequently Octa. They enroll a new device, obtaining a valid authentication token. This step is particularly insidious as it doesn't involve malware or exploits but rather legitimate credentials, making it difficult to distinguish from a real employee login and thus evading traditional detections.
- SSO Session & SAS Control Plane Exploitation: With an SSO session established via the compromised IDP, attackers gain access to any application federated with Octa. They exploit features like Octa's app self-assignment to expand their reach within the SAS control plane, leveraging permissions already held by the compromised employee.
- Data Access and Exfiltration: Finally, they access and exfiltrate sensitive data, which is then published on dark web forums or extortion sites.
The speakers identified specific "chords" within this campaign:
- Identity Compromise Chord: This consistent sequence involves wishing/help desk social engineering leading to a password reset or MFA transfer, culminating in SSO compromise. This exact pattern has been observed across MGM, Caesars, Octa, Twilio, Markx and Spencer, and other targets for years. The tools and targets change, but the playbook remains.
- Infrastructure Chord: Attackers utilize consistent fishing domain templates (e.g.,
target/SSO.com,octalogin.targetcompany.com). While specific domains rotate, the templates and metadata persist. They also employ network anonymization services like MalvadVPN or residential proxies to mimic legitimate traffic, making IP-based blocking less effective. The categories of infrastructure persist even if the instances rotate. - Behavioral Chord (SAS Behavior): The lateral movement in these campaigns occurs not through traditional network hops but through SAS permissions. Attackers expand privileges by exploiting existing permissions within SaaS applications, rather than moving from server to server. This highlights a critical shift in how lateral movement should be detected.
The key takeaway for defenders is to move beyond simply asking, "Is this IP on my blocklist?" to "Does this sequence of actions match a known pattern?"
Amos Info Stealer: Infrastructural Pattern Persistence
The Amos info stealer campaign, in circulation since April 2023, specifically targets Mac OS devices, recognizing them as an "underdefended target." It follows a typical info stealer pattern, exfiltrating keychain passwords, browser credentials, crypto wallets, and system files. Initially a "smash and grab," it has evolved to incorporate persistence mechanisms.
The campaign mechanism, publicly reported around December 2023, involved attackers buying Google ad spaces for Mac OS-related issues (e.g., "USB not working"). These ads led users to AI chats (e.g., Claude, ChatGPT, Grok chats) that instructed them to copy and execute a specific terminal command.
The technical investigation by Samhita revealed persistent patterns despite indicator rotation:
- Initial Malware Delivery: The terminal command would download a first-stage malware from a specific endpoint (e.g.,
cleanGPT). This script would prompt the user for their password and check if it was running in a VM machine before downloading the second stage. - Second Stage and Domain Pivoting: The second stage, the Amos info stealer, was initially hosted on the same domain. However, Samhita's research showed rapid domain rotation. By analyzing TLS issuers (specifically WE1, a Google Services issuer) and endpoint naming conventions, new domains were discovered.
- Even when a new domain was found, it often hosted the same
cleanGPTendpoint, which then pointed to another new domain for the second stage (e.g.,cleaner1update). - Crucially, simply changing the domain resulted in a completely new hash for the malware, reinforcing the low pain for attackers to bypass hash-based detections.
- Persistent Infrastructural Preferences:
- TLS Provider Preferences: Attackers consistently used Google Services TLS issuers (
WE1, and laterE7,E8—which are from the same intermediary CAs). This preference provides a more stable detection point than rotating domains. - Endpoint Naming Conventions: Endpoints like
cleanGPT,cleaner1update, andhiddenfileswere reused across different domains. - Fixed Ad Spaces and Methodology: The attackers continued to buy ad space for generic Mac OS issues and employed the "copy-paste methodology" via AI chats and official-looking support pages.
- Evolving Obfuscation: In more recent, active campaigns, Samhita observed a shift from simple Base64 encoding to more complex obfuscation, such as hex encoded and gunzip compressed payloads, indicating attackers adapt their techniques when domains are tracked.
The "chords" observed here were the consistent use of specific TLS issuers, the reuse of endpoint naming conventions, and the overall "fix-it" page and copy-paste social engineering methodology, even as domains and hashes changed rapidly.
Demo / Proof of Concept
▶ Watch: Critiquing the traditional, indicator-heavy CTI model (6:00)
While the presentation did not feature a live, interactive demonstration in the traditional sense, the comprehensive breakdown of the Scattered Spider/Shiny Hunters and Amos info stealer campaigns served as powerful, real-world proof-of-concept examples for the "threat chords" methodology. Samhita Vempatti's detailed walk-through of her investigation into the Amos info stealer's domain pivoting and obfuscation effectively demonstrated how a researcher can apply the "chords" concept to uncover new adversary infrastructure and evolving TTPs, even when atomic indicators are rapidly changing.
For the Scattered Spider/Shiny Hunters case, the speakers meticulously mapped the adversary's consistent operational playbook—from OSINT and social engineering through identity provider compromise and SaaS privilege escalation—across multiple high-profile breaches. This sequential analysis highlighted the enduring "identity compromise chord" and "behavioral chord" that persist regardless of the specific company or employee targeted.
Similarly, Samhita's deep dive into the Amos info stealer illustrated how she pivoted from a single reported malicious domain to discover an entire network of new, active infrastructure. By focusing on TLS issuers (e.g., the recurring WE1 Google Services issuer) and consistent endpoint naming conventions (cleanGPT, cleaner1update, hiddenfiles), she showcased how these more stable "infrastructural chords" allowed her to track the adversary's movements and adaptations (like the shift to hex encoded and gunzip compressed payloads) even as domains and hashes were frequently rotated. These case studies collectively served as compelling practical demonstrations of the talk's central thesis: that patterns and preferences of threat actors consistently "outlive the atomic indicators."
Defensive Implications
▶ Watch: Why indicators fail: They're 'designed to burn' (6:45)
The central message for defenders is a critical shift in mindset: move away from merely asking, "Is this IP on my blocklist?" to instead asking, "Does this sequence of actions actually match a known pattern?" This entails prioritizing the detection of threat chords over individual notes.
The speakers provided a four-step process for extracting effective threat intelligence through research:
- Prioritization: Identify the subset of risks most relevant to your organization. This requires understanding your industry and business context to focus on threats like fishing, info stealers, or persistent campaigns that pose the biggest threat.
- Time-Boxed Research: Research can be a rabbit hole. It's crucial to set time limits to ensure meaningful value extraction, explore alternate hypotheses, and prevent excessive delving into specifics that may not yield actionable intelligence.
- Analyze: Uncover patterns in the data. This phase is critical for identifying detection gaps, coverage blind spots, and even discovering that necessary log sources are not being collected. Recognizing "we don't even log this particular thing" is a meaningful outcome.
- Report: Document findings thoroughly. The goal is concrete output, assuming that someone else might pick up the research later. Comprehensive documentation ensures continuity and value for future teams.
Beyond research, adopting a "threat intelligence way of thinking" involves:
- Contextual Analysis: Understand attacker behavior and its specific implications for your organization.
- Identifying Relevant Data Sources: Not all log sources are equally valuable. Research what provides the most pertinent information for detecting identified threats.
- Stakeholder Prioritization: Understand the needs of teams consuming threat intelligence (e.g., executive reporting, SOC analysts) to deliver tailored and impactful insights.
To build sustainable and scalable CTI practices, organizations should implement:
- Formal CTI Processes: Structure and repeatability are key to long-term success.
- Context-Rich Threat Intelligence Feeds: Choose feeds that provide behavioral context, not just raw IOCs.
- Collaboration and Sharing: Engage with industry partners and peers to gain real-time awareness of current campaigns, rather than waiting for public reports months later.
Specific actionable recommendations for different roles:
- For those outside security/CTI teams:
- Connect with your organization's threat intelligence team.
- Educate yourself on identity actions, as they are often the starting point for intrusions.
- Surface any valuable log sources you have access to that might benefit the security team.
- For security teams/SOC analysts:
- Start with identity abuse: This is a primary perimeter defense area, as employees are increasingly targets for various threat actors.
- Focus on detecting sequences, not atomic alerts: Group logs from various sources to see the "bigger picture." While time-consuming, this approach yields higher value.
- Focus on data movement: Monitor for patterns in how data is accessed and exfiltrated.
- Leverage AI: The speakers acknowledged the slowness of manual pattern detection and suggested automating this process through AI and agentic workflows as an internal goal.
- Monitor TLS Issuer Preferences: As demonstrated with the Amos info stealer, consistent TLS issuers (e.g., Google Services CAs like WE1, E7, E8) are more persistent infrastructural chords than frequently rotating domains or IPs. This provides a valuable, harder-to-change indicator for detection and pivoting.
Ultimately, the defensive implication is clear: by "hearing the chords," organizations can accelerate their ability to find and respond to threat actor activity sooner, building a more resilient security posture that anticipates adversary pivots rather than merely reacting to ephemeral indicators.
Key Takeaways
- Adversary "Chords" Outlive "Notes": The fundamental behavioral patterns and operational playbooks of threat actors (threat chords) persist over time, even as specific IOCs (IPs, hashes, domains, tools) are rapidly rotated and "burned."
- Traditional CTI is "Bottom-Heavy": Many current CTI programs disproportionately focus on easily changed atomic indicators at the base of the Pyramid of Pain, leading to reactive defenses that are quickly bypassed.
- Identity Compromise is a Persistent Chord: For sophisticated groups like Scattered Spider and Shiny Hunters, social engineering leading to MFA reset and SSO compromise is a highly effective and consistently used "identity compromise chord" that is difficult for attackers to change.
- Infrastructural Patterns Provide Durable Indicators: While domains and IPs change, underlying infrastructural chords like consistent TLS issuers (e.g., Google Services CAs) and endpoint naming conventions offer more stable and valuable detection points.
- Shift to Sequence-Based Detection: Defenders must move from blocking individual atomic alerts to detecting sequences of actions and behavioral chords (e.g., lateral movement via SAS permissions), which provides a more robust defense against adaptive adversaries.
- Prioritized, Contextual Research is Crucial: Effective threat intelligence requires time-boxed, prioritized research focused on organizational risks, thorough analysis to uncover patterns and detection gaps, and comprehensive documentation for long-term value.
About the Speaker(s)
Karthika and Samhita Vempatti are both cybersecurity researchers at Adobe. Their work primarily focuses on threat actor profiling and adversary tracking, aiming to understand the evolving landscape of cyber threats and provide actionable intelligence to bolster defenses. Their expertise in breaking down complex attack chains and identifying persistent adversary behaviors forms the foundation of their "Threat Chords" methodology.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent, well-structured threat intelligence talk that repackages the Pyramid of Pain into a music metaphor and applies it to two real campaigns. The Amos infra-pivoting case study shows genuine research chops, but the conceptual framework is familiar territory dressed up in new branding — nothing here will surprise a seasoned CTI practitioner.
Heather Calloway (CISO) — SOLID
A well-structured and technically credible talk that makes a genuine case for TTP-focused intelligence over IOC chasing — but it stays in analyst territory and never fully crosses into the governance and program decisions that would make it land harder. Useful for SOC teams and CTI practitioners; limited value for security leaders trying to decide where to invest.