Data-Driven Clustering of Malicious Actor Profiles Based on Machine Learning Analysis of Attack Patterns in Cyber-Threat Intelligence Feeds
Effective defense measures in the constantly changing field of cybersecurity depend on knowing and recognizing cyber-threat actors and their attack patterns. In today’s changing threat landscape, organizations are managing their cybersecurity with increasingly proactive methods. Building a proactive and successful cybersecurity strategy requires grouping cyber-threat actors according to attack patterns. It offers insightful information that enables firms to react to risks more effectively. Using cyber-threat intelligence data, this study suggests a mechanism for grouping cyber-threat actors according to their similar attack patterns. To find out how well different clustering strategies group similar threat actors, they are put into practice and assessed. The results show how the suggested methodology might improve threat detection and response capabilities, with spectral clustering achieving the best performance (silhouette score: 0.63, adjusted Rand index (ARI): 0.58, and Calinski–Harabasz (CH) index: 230.3) and K -means performing comparably (silhouette score: 0.61, ARI: 0.55, and CH index: 220.1). Five distinct behavioral clusters were identified, grouping threat actors such as APT28, FIN7, Lazarus, and Turla based on shared attack patterns including exploit-based intrusion, credential harvesting, and command-and-control obfuscation. By advanced clustering techniques, this work aims to enhance threat actor detection and profiling, leading to more proactive and successful cybersecurity measures.