Threat Actors
Threat Actors
Entity responsible for event that has impact on safety of another entity
Called a Malicious Actor
Attributes
Describes characteristics of the attacker
Useful to categorize the motivation
Why
random or deliberate
Attributes of threat actors
Internal/external
Attacker is inside the house
They are outside trying to get in
Resources/funding
No money
limited resources
Large money
Large amount attack vectors
Level of sophistication/capability
None
Blindly runs scrips or automated scans
Large
Write their own attack malware and scripts
Motivations of Threat Actors
What was the purpose of the attack?
Motivations:
Data exfiltration
Espionage
Service Disruption
Blackmail
Financial gain
Political Beliefs
Ethical
Revenge
Disruption
War
Nation State
External entity
Government or agency
Multiple motives
Data exfil, philosophical, revenge, disruption, war
Large resources
constant attacks, multiple at the same time
Advanced Persistent Threat (APT)
High sophistication
Experienced attackers creating custom attack types to target of militaries, utilities, financial
Unskilled attackers
Runs pre-made scripts without any knowledge of what is going on under the hood
Motivated by the hunt
Can be external and internal
Not sophisticated and limited resources
Looks for low hanger fruit
Hacktivist
Hacker with a purpose
philosophy, political, revenge
Often external, potential internal
Strong sophistication
Specific hacks
DoS, website defacing, private document release
Funding limited
potential fundraising events
Insider Threat
Motivated by revenge or financial gain
Extensive Resources
Uses organizations resources
Medium level of sophistication
Often knows where the data they want is and how to bypass the in place security
Organized Crime
Professional criminals
Money is the main motive
Mostly external entity
Very sophisticated
best hacking money can buy
Crime is extremely organized
hacking, manager, seller
Shadow IT
Group or department that works around the existing polices of the IT department
Build own infrastructure and download own programs
Does not have to deal with limitations such as change control and budgets
Limited resources
Medium Sophistication
Potential IT knowledge from none to little