Question

Difficulty: Very hardThreat Actors, Attributes, and Attack Vectors

A security operations team investigating an incident at a global maritime logistics enterprise discovers that an unauthorized external entity compromised an edge API endpoint used by a third-party tracking partner. The threat actor utilized legitimate, stolen developer API tokens to gain access. Over an eight-month period, the actor made subtle, highly targeted modifications to cargo manifest metadata to delay specific dual-use technology shipments across international borders. The actor avoided deploying malware, exfiltrating bulk data, or disrupting general operations to evade detection by automated security controls. Based on these observed tactics, techniques, and procedures (TTPs), which threat actor profile and attribute combination is MOST likely responsible for this attack?

  1. A
    Organized crime syndicate motivated by financial gain and leveraging rapid automated exploitation tools
  2. Nation-state threat actor possessing high sophistication, extensive funding, and long-term geopolitical intentAnswer
  3. C
    Hacktivist collective seeking public ideological disruption using low-sophistication off-the-shelf scripts
  4. D
    Unintentional insider threat resulting from shadow IT systems misconfiguring third-party integration controls

Answer

The threat actor profile most likely responsible is a nation-state threat actor possessing high sophistication, extensive funding, and long-term geopolitical intent.
The correct answer identifies a nation-state actor because the attack TTPs emphasize long-term stealth (eight months of living-off-the-land without malware), a supply chain attack vector via third-party API trust, and strategic disruption of sensitive dual-use shipments. These characteristics align strictly with state-sponsored Advanced Persistent Threats (APTs) driven by geopolitical goals and supported by significant financial and technological resources.

Step-by-Step Solution

1
Analyze the operational behavior and attack vector described in the incident report.
The adversary leveraged a third-party supply chain vector (stolen developer API keys) to maintain stealthy persistence for eight months without deploying malware.
Identifying the vector highlights the level of planning and operational discipline required.
2
Evaluate the primary intent and motivation demonstrated in the scenario.
The goal was subtle sabotage of dual-use hardware shipments over an extended period rather than data theft for resale or ransom extortion.
Geopolitical sabotage alignment strongly indicates state-sponsored motives rather than financial or publicity-driven goals.
3
Correlate actor attributes (sophistication, resources, funding) with threat actor categories.
High sophistication, extensive resources, and patience are defining characteristics of nation-state Advanced Persistent Threat (APT) groups.
Only well-funded nation-state entities typically conduct prolonged, low-and-slow supply chain operations for strategic intelligence or disruption objectives.

Key Concept

Threat Actor Categorization and Attribute Mapping
Estimated Time:2m 0s
Rate this question