5.
Compare and contrast common threat actors and motivations
Threat Actors
➢ Threat actors are entities or individuals that engage in cyber activities, ranging from
gentle to malicious.
➢ There are six distinct types of threat actors: nation states, unskilled attackers,
hacktivists, insider threats, organized crime groups, and shadow IT, defined as
follows:
Nation state:
➢ These are government-sponsored entities that engage in cyber operations to further
their national interests.
➢ Often possessing substantial resources and advanced technical capabilities, nation
states can launch sophisticated attacks, such as spying, data theft, and even sabotage.
➢ Their motives can vary widely, from influencing other countries’ elections to gaining
political influence on the global stage.
Advanced Persistent Threat (APT):
➢ An APT is a sophisticated and focused cyberattack launched by well-funded and
highly skilled opponents, such as nation-backed agents or organized cybercriminal
groups.
➢ APTs are recognized for their ability to break into a specific system or network, stay
hidden for a long time, and quietly steal important data or cause damage bit by bit
over an extended period.
Unskilled attacker:
➢ Unskilled attackers lack technical skill and often resort to using off the-shelf tools.
➢ These individuals are with minimal understanding of hacking
methodologies.
➢ They can still cause significant disruption and data breaches.
Hacktivists:
➢ Hacktivists are individuals or groups driven by ideological, political, or social
motives.
➢ They employ cyber tactics to promote a cause, raise awareness, or enact change.
➢ Often, their attacks involve defacing websites, leaking sensitive
information, or disrupting online services.
Insider threats:
➢ Insider threats originate from within an organization.
➢ These threat actors include employees, contractors, or business partners who misuse
their access to compromise data, systems, or networks.
➢ Insider threats can be unintentional (such as employees falling victim to phishing
attacks) or intentional when disgruntled personnel seek revenge or financial gain.
Organized crime:
➢ These threat actors operate like cybercriminal enterprises, engaging in activities such
as ransomware attacks, credit card fraud, and identity theft.
➢ Their operations are characterized by a hierarchical structure, division of labour, and a
focus on monetary gains.
Shadow IT:
➢ Shadow IT refers to technology used within an organization without proper approval or
oversight from the IT department.
➢ Employees might use unauthorized applications or devices out of a desire to enhance
their productivity or streamline their work processes, rather than with any malicious
intent.
Attributes of Actors
➢ There are three critical attributes of threat actors: internal/external distinction,
resources/funding availability, and level of sophistication/capability.
Internal/External distinction
Internal threat actors:
➢ These originate from within an organization’s own ranks, often taking advantage of
their familiarity with systems, networks, and processes.
➢ They can be employees, contractors, or even business partners.
➢ They may exploit their access to data and systems to launch attacks, whether
intentionally or inadvertently.
➢ These attacks could stem from various motivations, such as financial gain, revenge, or
personal grievances.
External threat actors:
➢ These come from outside the organization and include a wide range of entities, from
individual hackers to organized crime groups and nation states.
➢ External threat actors typically lack direct knowledge of the target’s internal systems,
which may lead them to rely on inspection and social engineering to gain access.
➢ Their attacks can vary greatly and can encompass spying, data theft, and financial
fraud.
Resources/Funding availability
Well-resourced threat actors:
➢ These actors have access to substantial resources, which may be in the form of financial
backing, advanced technology, or even government support.
➢ Nation state and APT threat actors fall into this category, often possessing significant
budgets, specialized teams, and cutting-edge tools.
➢ Their attacks can be highly sophisticated and involve well-disguised techniques
designed to avoid detection.
Limited resources:
➢ Some threat actors, especially small-scale cybercriminals or unskilled attackers,
may operate with limited resources.
➢ They might rely on readily available hacking tools, social engineering, or other low-
cost methods.
➢ They can still be effective, particularly when targeting less secure targets.
Level of sophistication/capability
Highly sophisticated threat actors:
➢ These actors possess advanced technical skills and deep knowledge of various attack
vectors. Nation states, APT groups, and certain organized crime syndicates often fall
into this category.
➢ Their attacks involve zero-day vulnerabilities, custom malware, and complex
evasion techniques.
Less sophisticated threat actors:
➢ Unskilled attackers and some cybercriminals operate with less advanced technical
skills.
➢ They might rely on easily accessible tools, pre-made malware, and simpler attack
methods.
➢ Despite their limited capabilities, their attacks can still cause significant disruptions
and data breaches.
Motivations
➢ These motivations span a diverse spectrum, ranging from financial gain to political
ideology.
Data Exfiltration:
➢ Cybercriminals often target personal and financial data to later sell on the dark web.
➢ Organizations are at risk of intellectual property theft, which can have far-reaching
economic implications, as well as breaches of customer data that result in tarnished
reputations and legal consequences.
Espionage (Spying):
➢ Espionage driven motivations involve through networks, systems, and databases of
adversaries to collect sensitive information, government secrets, or industrial
espionage.
Service Disruption:
➢ This motivation can be driven by political, ideological, or personal reasons, with attacks
targeting critical infrastructure, public services, and communication networks.
Blackmail:
➢ Cybercriminals exploit stolen data, personal information, or compromising content to
force victims.
➢ Ransomware attacks have risen to prominence, paralyzing organizations by
encrypting their data and demanding hefty ransoms for its release.
Financial gain:
➢ A persistent driving force, a desire for financial gain compels
cybercriminals to target financial institutions, businesses, and individuals.
➢ From credit card fraud to cryptocurrency theft, the quest for monetary reward
fuels an array of cyberattacks.
Philosophical/political beliefs:
➢ They deface websites, leak sensitive information, and disrupt online services to
draw attention to specific causes or ideologies.
Ethics:
➢ They operate with a sense of ethical responsibility, identifying vulnerabilities and
exposing them to encourage better security practices.
➢ These ethical hackers, or “white hat” hackers, play a vital role in uncovering
vulnerabilities before malicious actors can exploit them.
Revenge:
➢ The desire for revenge can prompt cyberattacks aimed at causing personal or
organizational harm.
➢ Dissatisfied employees, former partners, or individuals with personal vendettas may
resort to digital means to exact revenge.
Disruption/chaos:
➢ Cyber threat actors may target public and private entities with the intention of creating
an environment of instability and uncertainty.
War:
➢ Nation states engage in cyber operations to gain superiority in conflicts, employing
cyberattacks as a modern form of warfare.