About ThreatPaper
What ThreatPaper Is
ThreatPaper is a research publication that produces structured, deeply technical research papers on real high-impact cybercrime incidents worldwide. Every published piece is a full research paper — technical breakdown, verified timeline, attacker TTPs, legal response, and defensive lessons.
ThreatPaper focuses on incidents that are technically rich and genuinely educational. Each case is selected for its depth, novelty, and the lessons it offers to defenders, researchers, and policymakers.
What ThreatPaper Is Not
- Not a news aggregator — we don't rewrite press releases
- Not a CVE feed — we don't catalog vulnerabilities
- Not a blog — every piece follows a rigorous research structure
- Not a threat intelligence platform — we don't provide real-time feeds
Editorial Methodology
Cases are selected on technical significance, real-world impact, and educational value. Every published piece carries full source attribution and follows the same analytical structure, so papers can be compared against one another.
Each paper is built the same way: every specific claim checked against a cited primary source, technical analysis of the attack chain and attacker tradecraft, a timeline reconstructed from multiple independent sources, and an account of the legal and regulatory response.
Where a claim cannot be confirmed, it is marked unverified rather than asserted. Where a paper is materially corrected after publication, the change is recorded in a corrections log on the paper itself rather than applied silently.
Who Runs ThreatPaper
ThreatPaper is an independently run publication. Editorial decisions — what gets covered, what meets the evidentiary standard, and what is published — are made in-house rather than by any vendor, sponsor, or client.
Research is contributed by anyone who meets the standard, and every submission is reviewed before publication. Contributors keep credit on their work; their published papers are listed on the contributors page.
Common Questions
- What is ThreatPaper?
- ThreatPaper is an open research publication that produces structured, source-verified papers on real cybercrime incidents. Each paper covers the attack chain, a verified timeline, attacker tradecraft mapped to MITRE ATT&CK, defanged indicators of compromise, the legal and regulatory response, and defensive lessons. It is not a news site and not a CVE feed.
- How does ThreatPaper verify what it publishes?
- Every specific claim must cite a source, and key claims are cross-checked against at least two independent sources. Primary sources come first: government advisories, court filings, regulatory notifications, and first-party incident reports. Each paper carries a Verification of Claims section rating every claim Verified, Partially verified, or Unverified, so readers can see what is established and what is not.
- How does ThreatPaper handle attribution?
- Attribution is reported, not asserted. Papers state who attributed an incident, on what evidentiary basis, and at what confidence, reproducing the assessments of the cited sources. Where no authority has attributed an incident, the paper says so. Individuals are named only where public court filings or official statements already name them, and an accusation is never presented as a conviction.
- Can anyone contribute research to ThreatPaper?
- Yes. Anyone can create an account and submit a paper. Every submission is reviewed by an editor before publication and is either approved with a note or returned with specific changes. Authors can revise and resubmit without limit, and keep credit on published work.
- How are contributor standings and tiers calculated?
- Score is ten points for each published paper, plus the net votes readers gave it (upvotes minus downvotes), floored so a single unpopular paper cannot drag a contributor below zero. Papers alone would reward volume, which is the opposite of what this publication is for — three excellent papers should outrank ten thin ones. Tiers are earned by crossing a threshold of both papers and score, and once earned they are kept: Contributor at 1 paper, Analyst at 3 papers and 40 points, Researcher at 8 and 120, Senior Researcher at 15 and 300, Distinguished Researcher at 30 and 700. A contributor with no published papers is unranked. Full standings are at /contributors.
- Are the indicators of compromise safe to use?
- All network indicators are published defanged, for defensive use: blocking, hunting, and detection engineering. Papers do not carry working exploit code, live credentials, or unredacted victim personal data.
- What happens when a published paper turns out to be wrong?
- Corrections are published in a corrections log at the foot of the paper, naming what was wrong and what it should say, rather than being applied silently. The log is treated as part of the record.
Contact
For enquiries, corrections, or case suggestions, write to contact@threatpaper.com.