Question

Difficulty: MediumThreat Actors, Attributes, and Attack Vectors

A regional water treatment utility discovers an advanced network intrusion. Forensic investigators determine that the threat group maintained undetected persistence within the operational technology (OT) network for over nine months. Rather than deploying ransomware or causing immediate service disruption, the group focused exclusively on collecting SCADA configuration files and mapping control system logic. Which TWO of the following threat actor attributes and vector profiles most accurately describe this incident? (Select TWO)

  1. Nation-state threat actor operating with high sophistication, extensive funding, and geopolitical espionage motives.Answer
  2. Supply chain compromise of a trusted third-party software vendor used for remote industrial control maintenance.Answer
  3. C
    Hacktivist collective seeking immediate financial profit and public notoriety through automated ransomware deployment.
  4. D
    Script kiddie utilizing publicly available automated scanner tools to execute opportunistic distributed denial-of-service (DDoS) attacks.

Answer

The incident is best characterized by a nation-state threat actor motivated by geopolitical espionage and high-sophistication persistence, along with a supply chain attack vector leveraging trusted third-party software management access.
The scenario describes key indicators of a nation-state actor (Advanced Persistent Threat): high technical sophistication, long-term covert persistence, and strategic reconnaissance against critical infrastructure without financial demands. Furthermore, exploiting trusted third-party maintenance software (supply chain vector) is a primary method for such sophisticated actors to infiltrate air-gapped or segmented industrial control networks.

Step-by-Step Solution

1
Analyze the threat actor motivation and behavior indicators from the scenario.
The prolonged nine-month persistence, lack of financial extortion (ransomware), focus on critical infrastructure (SCADA/OT), and passive intelligence gathering point directly to an Advanced Persistent Threat (APT) backed by a nation-state.
Nation-state actors prioritize strategic espionage, low visibility, and long-term operational access over quick monetary gain.
2
Evaluate the attack vector characteristics suited for stealthy, high-target environments.
Exploiting third-party maintenance vendor software provides an indirect, trusted entry point that evades standard perimeter controls.
Supply chain compromises allow sophisticated threat actors to leverage existing trust relationships and gain deep access into segmented networks.

Key Concept

Threat Actor Attributes and Attack Vectors
Rate this question