Atlantic Council maps offensive cyber proliferation
A policy primer proposes a five-pillar framework—vulnerability research, malware development, C2, operations, and training—to better understand and counter the proliferation of offensive cyber capabilities.
This Atlantic Council issue brief argues that existing counter-proliferation efforts, such as the Wassenaar Arrangement, focus too narrowly on malware and command-and-control export controls, missing the broader lifecycle of offensive cyber capability (OCC) development. The authors propose reframing OCC proliferation around five pillars: vulnerability research and exploit development, malware payload development, technical command and control, operational management, and training and support. They describe how self-regulated (underground criminal forums like 0day.today, exploit.in, dark0de) and semi-regulated markets (state agencies, private vendors, and Access-as-a-Service firms like NSO Group) supply these capabilities to governments, criminals, and private actors with varying degrees of sophistication and regulation.
The report uses Stuxnet/Operation Olympic Games as a case study illustrating that sophisticated offensive operations require far more than malware alone—citing the use of five zero-days, custom SCADA targeting, and sustained interagency collaboration attributed to Israel and the United States. It also discusses state-linked vulnerability research programs, including China's CNITSEC/CNNVD and the US Vulnerabilities Equities Process, noting research showing China's national vulnerability database delayed publication of bugs used by Chinese APTs, and later altered disclosure dates after being caught. NSO Group's Pegasus spyware is referenced as an example of AaaS firms providing government-grade offensive capability to over 45 countries, with documented misuse against journalists and human rights activists.
Overall the piece is a policy and research document rather than an incident report: it does not describe a new active campaign, but instead synthesizes historical and structural evidence to argue for more nuanced counter-proliferation regulation targeting the full OCC supply chain rather than just malware components.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/a-primer-on-the-proliferation-of-offensive-cyber-capabilities
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free