Skip to content
Open access

Data-Driven Clustering of Malicious Actor Profiles Based on Machine Learning Analysis of Attack Patterns in Cyber-Threat Intelligence Feeds

Aug 2026 · AI Computer Science and Robotics Technology · 0 citations · 33 references

Abstract

Effective defense measures in the constantly changing field of cybersecurity depend on knowing and recognizing cyber-threat actors and their attack patterns. In today’s changing threat landscape, organizations are managing their cybersecurity with increasingly proactive methods. Building a proactive and successful cybersecurity strategy requires grouping cyber-threat actors according to attack patterns. It offers insightful information that enables firms to react to risks more effectively. Using cyber-threat intelligence data, this study suggests a mechanism for grouping cyber-threat actors according to their similar attack patterns. To find out how well different clustering strategies group similar threat actors, they are put into practice and assessed. The results show how the suggested methodology might improve threat detection and response capabilities, with spectral clustering achieving the best performance (silhouette score: 0.63, adjusted Rand index (ARI): 0.58, and Calinski–Harabasz (CH) index: 230.3) and K -means performing comparably (silhouette score: 0.61, ARI: 0.55, and CH index: 220.1). Five distinct behavioral clusters were identified, grouping threat actors such as APT28, FIN7, Lazarus, and Turla based on shared attack patterns including exploit-based intrusion, credential harvesting, and command-and-control obfuscation. By advanced clustering techniques, this work aims to enhance threat actor detection and profiling, leading to more proactive and successful cybersecurity measures.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.