Threat Actor Types
| Actor | Sophistication | Resources | Motivation | Example |
|---|---|---|---|---|
| Nation-State / APT | Very High | Government-funded | Espionage, sabotage, geopolitical goals | Stuxnet (Iran nuclear program) |
| Organized Crime | High | Well-funded | Financial gain | Ransomware gangs (REvil, LockBit) |
| Hacktivist | Medium | Moderate | Political/social agenda | Anonymous — DDoS attacks on government sites |
| Insider Threat | Varies | Privileged access | Revenge, financial, ideology, negligence | Disgruntled employee exfiltrating data |
| Script Kiddie | Low | Minimal | Fun, recognition, vandalism | Using downloaded exploit kits |
| Competitor | Medium–High | Corporate-funded | Industrial espionage | Stealing trade secrets, IP theft |
| Shadow IT | Low (unintentional) | Authorized users | Convenience (not malicious) | Employee using personal Dropbox for work files |
APT — Advanced Persistent Threat
APTs are characterized by:
- Advanced: Use zero-days, custom malware, sophisticated TTPs
- Persistent: Dwell in networks for months/years undetected (avg dwell time: ~200 days)
- Threat: Have specific, high-value targets (government, defense, critical infrastructure)
APT stages follow the Cyber Kill Chain: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives.
Threat Actor Attributes
- Internal vs. External: Internal actors have legitimate access; external must breach the perimeter
- Level of Sophistication: Ranges from unskilled (script kiddies) to nation-state level
- Resources / Funding: Impacts tooling capability and operational scale
- Intent / Motivation: Financial, ideological, revenge, espionage, chaos
Motivations Summary
Common motivations to know for the exam:
Financial
Ransomware, fraud, card skimming, BEC
Ransomware, fraud, card skimming, BEC
Espionage
Nation-state IP theft, insider data exfiltration
Nation-state IP theft, insider data exfiltration
Disruption / Chaos
DDoS, destructive malware (NotPetya)
DDoS, destructive malware (NotPetya)
Ideological
Hacktivism, defacement, leaking information
Hacktivism, defacement, leaking information
Revenge
Disgruntled employee sabotage
Disgruntled employee sabotage
War / Geopolitics
Critical infrastructure attacks
Critical infrastructure attacks
Exam Tip: Insider threats are the most dangerous because they have authorized access and knowledge of internal systems. They are the hardest to detect. Countermeasures: least privilege, separation of duties, DLP, user behavior analytics (UBA).