> ## Documentation Index
> Fetch the complete documentation index at: https://stem-docs.intellectualpoint.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat actors

> Learn who carries out cyberattacks, what motivates them, and how to recognize their methods.

## Who is attacking - and why?

Every cyberattack has a person or group behind it. In cybersecurity, you call them **threat actors** - individuals or organizations that intentionally exploit vulnerabilities in systems, networks, or people to cause harm or gain an advantage.

Understanding threat actors is one of the first things a security professional learns because *who* is attacking tells you *how* they will attack, *what* they are after, and *how much* effort they will invest.

<Info>
  A **threat actor** is any person, group, or entity responsible for a cyber event that impacts - or has the potential to impact - an organization's security.
</Info>

<Frame caption="Threat actors come in many forms">
  <img src="https://mintcdn.com/intellectualpoint/Z4o1TCU5ZOWJaHan/images/cyber/threat-actor-spy.png?fit=max&auto=format&n=Z4o1TCU5ZOWJaHan&q=85&s=9b18410b6b615c063835288ff1b20a00" alt="Silhouette of a spy figure representing threat actors" width="1200" height="1200" data-path="images/cyber/threat-actor-spy.png" />
</Frame>

***

## The six types of threat actors

<Frame caption="Cyber threats by the numbers - why every business needs security">
  <img src="https://mintcdn.com/intellectualpoint/Z4o1TCU5ZOWJaHan/images/cyber/cyber-threats-stats.png?fit=max&auto=format&n=Z4o1TCU5ZOWJaHan&q=85&s=54cf80ca776c16650eaf2fd62249e1b1" alt="Statistics showing 28% of data breaches involve small businesses, 44% have no cyber defenses, and 57% of attacks involve phishing" width="1200" height="670" data-path="images/cyber/cyber-threats-stats.png" />
</Frame>

Not every attacker is the same. Threat actors range from bored teenagers running downloaded scripts to elite government-funded teams with billion-dollar budgets. Here are the six categories you need to know.

### 1. Cybercriminals

**Motivation:** Money - always money.

<Frame caption="Cybercriminals are motivated by financial gain">
  <img src="https://mintcdn.com/intellectualpoint/AND_FRetZL1c0nBd/images/cyber/cybercriminal.png?fit=max&auto=format&n=AND_FRetZL1c0nBd&q=85&s=94f436127ce4fa8129123a6fc7de76ec" alt="Cartoon of a criminal running with bags of money" width="220" height="222" data-path="images/cyber/cybercriminal.png" />
</Frame>

Cybercriminals treat hacking as a business. They steal credit card numbers, deploy ransomware, commit identity theft, and sell stolen data on dark web marketplaces. Many operate as organized crime groups with defined roles: developers build the malware, operators deploy it, and money mules launder the profits.

| Attribute      | Detail                                                     |
| -------------- | ---------------------------------------------------------- |
| Motivation     | Financial gain                                             |
| Sophistication | Low to high (varies widely)                                |
| Funding        | Self-funded through criminal profits                       |
| Common attacks | Ransomware, phishing, credit card skimming, identity theft |

<Tip>
  **Real-world example:** In May 2021, the criminal group DarkSide deployed ransomware against **Colonial Pipeline**, shutting down fuel distribution across the eastern United States. The company paid a \$4.4 million ransom - though the FBI later recovered most of it.
</Tip>

### 2. Hacktivists

**Motivation:** Ideology, politics, or social causes.

Hacktivists use hacking as a form of protest. They deface websites, leak confidential documents, and launch denial-of-service attacks to draw attention to causes they believe in. Their targets are usually governments, corporations, or organizations they view as unethical.

| Attribute      | Detail                                     |
| -------------- | ------------------------------------------ |
| Motivation     | Political, ideological, or social activism |
| Sophistication | Low to moderate                            |
| Funding        | Minimal - mostly volunteer efforts         |
| Common attacks | Website defacement, data leaks, DDoS       |

<Tip>
  **Real-world example:** The collective **Anonymous** has launched operations against governments, corporations, and organizations worldwide. Their signature move: replacing a target's homepage with a message and the Guy Fawkes mask.
</Tip>

### 3. Nation-state actors

**Motivation:** Strategic national interests - espionage, disruption, or warfare.

These are government-sponsored hackers. They have enormous budgets, advanced tools, and time on their side. Their goals include stealing military secrets, disrupting foreign infrastructure, influencing elections, and gaining economic advantages through intellectual property theft.

| Attribute      | Detail                                                      |
| -------------- | ----------------------------------------------------------- |
| Motivation     | Espionage, sabotage, geopolitical advantage                 |
| Sophistication | Very high                                                   |
| Funding        | Government-backed (effectively unlimited)                   |
| Common attacks | Espionage, infrastructure sabotage, supply chain compromise |

<Warning>
  Nation-state actors are considered the most dangerous threat actor category. They have the patience, funding, and technical capability to breach even well-defended organizations.
</Warning>

### 4. Advanced persistent threats (APTs)

**Motivation:** Long-term strategic access.

APTs are not a separate motivation category - they are a *method*. APT groups (often nation-state backed) gain access to a network and remain hidden for months or even years. They move slowly, avoid detection, and extract data over time.

The term "advanced" refers to their sophisticated techniques. "Persistent" means they maintain access continuously. "Threat" means they cause real damage.

| Attribute      | Detail                                                  |
| -------------- | ------------------------------------------------------- |
| Motivation     | Long-term intelligence gathering                        |
| Sophistication | Extremely high                                          |
| Funding        | Typically government-sponsored                          |
| Common attacks | Zero-day exploits, custom malware, supply chain attacks |

<Note>
  APT groups are often given numbers by security researchers. **APT29** (also called "Cozy Bear") is linked to Russian intelligence. **APT41** is associated with China and conducts both espionage and financially motivated attacks.
</Note>

### 5. Script kiddies

**Motivation:** Curiosity, bragging rights, or boredom.

Script kiddies use pre-built hacking tools and scripts without understanding how they work. They download attack software, watch YouTube tutorials, and target easy victims. While individually less dangerous, they can still cause real harm - especially when powerful tools are freely available online.

| Attribute      | Detail                                                                             |
| -------------- | ---------------------------------------------------------------------------------- |
| Motivation     | Curiosity, reputation, thrill                                                      |
| Sophistication | Low                                                                                |
| Funding        | None                                                                               |
| Common attacks | Running pre-built exploits, DDoS using rented botnets, defacing unpatched websites |

<Info>
  Don't underestimate script kiddies. A teenager with a freely available exploit kit can still breach a company that hasn't patched its systems. The tools do the hard work - the attacker just points and clicks.
</Info>

### 6. Insider threats

**Motivation:** Varies - revenge, financial gain, negligence, or coercion.

<Frame caption="Insider threats hide among trusted users - the red face in a sea of friendly ones">
  <img src="https://mintcdn.com/intellectualpoint/AND_FRetZL1c0nBd/images/cyber/social-engineering-faces.png?fit=max&auto=format&n=AND_FRetZL1c0nBd&q=85&s=dd0945953b2b137ef99e9fe01117160e" alt="Grid of emoji faces with one angry red face representing an insider threat" width="401" height="358" data-path="images/cyber/social-engineering-faces.png" />
</Frame>

Insider threats come from people who already have legitimate access: employees, contractors, business partners, or former staff whose credentials haven't been revoked. They are one of the hardest threat categories to detect because they bypass external defenses entirely.

Insider threats fall into two sub-types:

* **Malicious insiders** - Intentionally steal data, sabotage systems, or sell access to outsiders
* **Negligent insiders** - Accidentally cause breaches through carelessness (clicking phishing links, misconfiguring systems, losing devices)

| Attribute      | Detail                                         |
| -------------- | ---------------------------------------------- |
| Motivation     | Revenge, money, negligence, coercion           |
| Sophistication | Varies (they already have access)              |
| Funding        | N/A (already inside)                           |
| Common attacks | Data theft, sabotage, accidental data exposure |

<Warning>
  Studies consistently show that insider threats account for a significant portion of data breaches. A firewall cannot stop someone who already has a badge and a login.
</Warning>

***

## Hacker hat classification

The security industry also classifies hackers by their *intent*, using a color-coded "hat" system.

<AccordionGroup>
  <Accordion title="Black hat hackers">
    **Black hats** are the villains. They hack without authorization and with malicious intent - to steal, destroy, or profit. Everything they do is illegal.

    * Break into systems without permission
    * Steal data, deploy ransomware, or sell exploits
    * Motivated by money, revenge, or power
  </Accordion>

  <Accordion title="White hat hackers">
    **White hats** are the heroes. They hack *with* authorization to find and fix vulnerabilities before the bad guys do. They are also called **ethical hackers** or **penetration testers**.

    * Hired by organizations to test security
    * Follow strict rules of engagement
    * Report everything they find
    * Careers: penetration tester, security consultant, red team operator
  </Accordion>

  <Accordion title="Gray hat hackers">
    **Gray hats** operate in a legally ambiguous zone. They find vulnerabilities *without* authorization but typically report them to the owner rather than exploiting them. Their intentions may be good, but their methods are technically illegal.

    * Find bugs without permission
    * Usually report findings to the organization
    * May demand payment (bug bounty) or publicly disclose if ignored
    * Legally risky - even helpful hacking without authorization can lead to prosecution
  </Accordion>
</AccordionGroup>

***

## Threat actor attributes

When analyzing a threat actor, security professionals evaluate three key attributes.

<Tabs>
  <Tab title="Internal vs. external">
    * **External threat actors** operate from outside the organization. They must breach perimeter defenses first.
    * **Internal threat actors** already have some level of authorized access. They are harder to detect because their activity may look normal.

    Most security tools are designed to catch external threats. Detecting insiders requires user behavior analytics (UBA) and strict access controls.
  </Tab>

  <Tab title="Funding level">
    * **Well-funded** actors (nation-states, organized crime) can buy zero-day exploits, build custom malware, and sustain operations for years.
    * **Low-budget** actors (script kiddies, lone hacktivists) rely on free tools, known exploits, and opportunistic targets.

    The level of funding directly predicts how sophisticated and persistent an attacker can be.
  </Tab>

  <Tab title="Sophistication level">
    * **High sophistication:** Custom-built malware, zero-day exploits, advanced evasion techniques, operational security to avoid attribution.
    * **Low sophistication:** Pre-built tools, known vulnerabilities, limited ability to adapt when defenses respond.

    A sophisticated attacker can modify their approach when detected. An unsophisticated attacker typically gives up or moves to an easier target.
  </Tab>
</Tabs>

***

## Shadow IT

**Shadow IT** refers to technology used within an organization without the knowledge or approval of the IT department. It creates hidden attack surfaces that security teams cannot monitor or protect.

<Info>
  **Intellectual Point example:** Imagine an employee stores client project files on their personal Google Drive instead of the company's approved SharePoint. If that personal account is compromised, the company's data is exposed - and the security team never even knew the data was there.
</Info>

Common shadow IT examples include:

* Using personal cloud storage (Dropbox, Google Drive) for work files
* Installing unapproved apps on work computers
* Using personal email for business communication
* Setting up unauthorized Wi-Fi access points
* Using consumer messaging apps (WhatsApp, Telegram) for work discussions

Shadow IT is not always malicious - employees often use unauthorized tools because they are faster or more convenient. But every unapproved tool is a blind spot for your security team.

***

## Key vocabulary

Master these terms - you will see them throughout the rest of the week.

| Term                 | Definition                                                                                            |
| -------------------- | ----------------------------------------------------------------------------------------------------- |
| **Threat actor**     | Any person, group, or entity responsible for a cybersecurity incident                                 |
| **Attack vector**    | The method or path an attacker uses to gain access (email, USB, network exploit)                      |
| **Attack surface**   | The total number of points where an attacker could try to enter a system                              |
| **Remediation**      | The process of fixing a vulnerability or responding to a security incident                            |
| **Threat feed**      | A real-time stream of data about current threats, indicators of compromise, and attack techniques     |
| **Foothold**         | The initial point of access an attacker establishes inside a network                                  |
| **Pivot**            | When an attacker moves from a compromised system to attack other systems on the same network          |
| **Lateral movement** | Moving through a network after initial access - hopping from system to system to reach the target     |
| **Fingerprinting**   | Identifying the specific software, versions, and configurations running on a target system            |
| **Footprinting**     | Gathering broad information about a target organization (domains, IP ranges, employees, technologies) |

***

## Exercise: identify the threat actor

Read each scenario and identify the threat actor type and their likely motivation.

<AccordionGroup>
  <Accordion title="Scenario 1">
    A group encrypts a hospital's patient records and demands \$500,000 in Bitcoin to restore access.

    **Answer:** Cybercriminal. Motivation: financial gain. This is a classic ransomware attack targeting critical infrastructure because hospitals are more likely to pay quickly.
  </Accordion>

  <Accordion title="Scenario 2">
    A teenager downloads a tool from a hacking forum and uses it to deface their school's website with a meme.

    **Answer:** Script kiddie. Motivation: curiosity and bragging rights. They used a pre-built tool and targeted an easy victim with poor security.
  </Accordion>

  <Accordion title="Scenario 3">
    A foreign intelligence agency spends six months quietly collecting emails from a defense contractor's executives.

    **Answer:** Nation-state actor / APT. Motivation: espionage. The long duration, stealth, and strategic target all point to a state-sponsored operation.
  </Accordion>

  <Accordion title="Scenario 4">
    An employee who was just told they are being laid off downloads the entire customer database to a USB drive on their last day.

    **Answer:** Insider threat (malicious). Motivation: revenge or personal gain. They used their legitimate access to steal data before losing it.
  </Accordion>

  <Accordion title="Scenario 5">
    A collective leaks thousands of internal emails from a large oil company to protest their environmental record.

    **Answer:** Hacktivists. Motivation: ideological - environmental activism. The leak is designed to embarrass and pressure the company, not to profit financially.
  </Accordion>

  <Accordion title="Scenario 6">
    An accounting employee clicks a phishing link and accidentally gives attackers access to the payroll system.

    **Answer:** Insider threat (negligent). The employee didn't act maliciously - they made a mistake. But the result is the same: the attacker now has access.
  </Accordion>
</AccordionGroup>
