A journal article written by my coauthors and I will be appearing in Volume 10 of Military Cyber Affairs. Below is a preview of the abstract:
Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and identified multiple previously undocumented relationships between ostensibly distinct ransomware groups. These findings demonstrate that natural language artifacts provide valuable attribution signals and highlight the potential of NLP-based profiling as a force multiplier for critical infrastructure defense and cyber threat intelligence.