A security team at a regional retail corporation is investigating a security incident involving unauthorized access to internal file servers. The attacker gained access using valid employee credentials purchased from an online broker, deployed commercially available ransomware within two hours of access, and left a ransom note demanding an immediate cryptocurrency payment. The investigation confirmed that no sensitive intellectual property was exfiltrated and no attempts were made to establish long-term persistence. Which threat actor category and attribute profile are most consistent with this attack?
- Organized crime motivated by financial gain utilizing commoditized toolsAnswer
- BNation-state adversary motivated by strategic intelligence gathering utilizing custom zero-day exploits
- CHacktivist collective motivated by ideological causes seeking public disruption
- DMalicious insider leveraging elevated administrative privileges for personal revenge
Answer
Organized crime motivated by financial gain utilizing commoditized tools
Organized crime threat actors are primarily motivated by financial profit. They frequently leverage compromised credentials purchased from access brokers and deploy off-the-shelf or ransomware-as-a-service (RaaS) toolkits to achieve fast monetization, matching all indicators in the scenario.
Step-by-Step Solution
Key Concept
Threat Actor Classification and Motivation Profiling