Threat Actors Flashcards
Threat Actor Motivations
■ Data Exfiltration
■ Blackmail
■ Espionage
■ Service Disruption
■ Financial Gain,
■ Philosophical/Political Beliefs
■ Ethical Reasons
■ Revenge
■ Disruption/Chaos
■ War
Threat Actor Attributes
■ Internal vs. External Threat Actors
■ Differences in resources and funding
■ Level of sophistication
Types of Threat Actors
Unskilled Attackers
Hacktivists
Organized Crime
Nation-state Actor
Insider Threats
Limited technical expertise, use readily available tools
Unskilled Attackers
Driven by political, social, or environmental ideologies
Hacktivists
Execute cyberattacks for financial gain (e.g., ransomware, identity theft)
Organized Crime
Highly skilled attackers sponsored by governments for cyber espionage or
warfare
Nation-state Actor
Security threats originating from within the organization
Insider Threats
IT systems, devices, software, or services managed without explicit organizational
approval
Shadow IT
■ Message-based
■ Image-based
■ File-based
■ Voice Calls
■ Removable Devices
■ Unsecured Networks
Threat Vectors and Attack Surfaces
Deception and Disruption Technologies
Honeypots
Honeynets
Honeyfiles
Honeytokens
Decoy systems to attract and deceive attackers
Honeypots
Network of decoy systems for observing complex attacks
Honeynets
Decoy files to detect unauthorized access or data breaches
Honeyfiles
Fake data to alert administrators when accessed or used
Honeytokens
Specific objective or goal that a threat actor is aiming to achieve through
their attack
Threat Actors Intent
Underlying reasons or driving forces that pushes a threat actor to carry
out their attack
Threat Actors Motivation
Unauthorized transfer of data from a computer
Data Exfiltration
Achieved through various means, such as ransomware attacks, or through
banking trojans that allow them to steal financial information in order to
gain unauthorized access into the victims’ bank accounts
Financial Gain
Attacker obtains sensitive or compromising information about an
individual or an organization and threatens to release this information to
the public unless certain demands are met
Blackmail
Some threat actors aim to disrupt the services of various organizations,
either to cause chaos, make a political statement, or to demand a ransom
Service Disruption
● Attacks that are conducted due to the philosophical or political beliefs of
the attackers is known as hacktivism
● Common motivation for a specific type of threat actor known as a
hacktivist
Philosophical or Political Beliefs