# Atlantic Council maps offensive cyber proliferation

Published: 2021-03-01 · Severity: low · Sectors: energy, government-national, defense
Canonical: https://vorant.io/reports/2d8eb217-1724-51a1-8263-b1ef1ab9a1cd/atlantic-council-maps-offensive-cyber-proliferation

> A policy primer proposes a five-pillar framework—vulnerability research, malware development, C2, operations, and training—to better understand and counter the proliferation of offensive cyber capabilities.

This Atlantic Council issue brief argues that existing counter-proliferation efforts, such as the Wassenaar Arrangement, focus too narrowly on malware and command-and-control export controls, missing the broader lifecycle of offensive cyber capability (OCC) development. The authors propose reframing OCC proliferation around five pillars: vulnerability research and exploit development, malware payload development, technical command and control, operational management, and training and support. They describe how self-regulated (underground criminal forums like 0day.today, exploit.in, dark0de) and semi-regulated markets (state agencies, private vendors, and Access-as-a-Service firms like NSO Group) supply these capabilities to governments, criminals, and private actors with varying degrees of sophistication and regulation.

The report uses Stuxnet/Operation Olympic Games as a case study illustrating that sophisticated offensive operations require far more than malware alone—citing the use of five zero-days, custom SCADA targeting, and sustained interagency collaboration attributed to Israel and the United States. It also discusses state-linked vulnerability research programs, including China's CNITSEC/CNNVD and the US Vulnerabilities Equities Process, noting research showing China's national vulnerability database delayed publication of bugs used by Chinese APTs, and later altered disclosure dates after being caught. NSO Group's Pegasus spyware is referenced as an example of AaaS firms providing government-grade offensive capability to over 45 countries, with documented misuse against journalists and human rights activists.

Overall the piece is a policy and research document rather than an incident report: it does not describe a new active campaign, but instead synthesizes historical and structural evidence to argue for more nuanced counter-proliferation regulation targeting the full OCC supply chain rather than just malware components.

## Mentioned in this report

- Vulnerabilities: CVE-2018-4878 (KEV)
- Threat actors: Chinese Ministry of State Security-linked APTs, NSO Group
- Malware: Pegasus, Stuxnet
- Campaigns: Operation Olympic Games

Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/a-primer-on-the-proliferation-of-offensive-cyber-capabilities

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2d8eb217-1724-51a1-8263-b1ef1ab9a1cd/atlantic-council-maps-offensive-cyber-proliferation.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
