Question

Difficulty: Very hardThreat Actors, Attributes, and Attack Vectors

An enterprise risk assessment team is categorizing threat entities involved in recent cyber incidents across various critical sectors. Match each incident narrative detailing specific adversary attributes, resources, and attack vectors on the left to the corresponding threat actor classification on the right.

  • An intrusion targeting a satellite telemetry facility used custom zero-day exploits in edge VPN firmware, established living-off-the-land persistence across isolated network enclaves, and systematically exfiltrated geopolitical communications over an 18-month period without making any financial demands.Nation-State / Advanced Persistent Threat (APT)
  • An adversary gained access to a health system's billing network using valid API credentials purchased on an underground forum, deployed automated double-extortion ransomware to lock patient management databases, and threatened to release private medical records unless a cryptocurrency ransom was paid within 72 hours.Organized Crime
  • A senior database Administrator with legitimate access to production storage buckets routinely bypassed corporate logging mechanisms to copy trade secret schematics to an personal cloud drive immediately prior to submitting a notice of resignation.Malicious Insider
  • A group of marketing employees integrated an unauthorized third-party automated data-scrubbing web service into corporate workflows to streamline lead processing, exposing sensitive client information via an unauthenticated public AWS S3 bucket configured by the vendor.Shadow IT

Answer

1 matches Nation-State / Advanced Persistent Threat (APT), 2 matches Organized Crime, 3 matches Malicious Insider, 4 matches Shadow IT.
Each scenario reflects distinct motivation, sophistication level, resource capacity, and attack vector signatures. Geopolitical espionage utilizing zero-day vulnerabilities maps to Nation-State actors; financial ransomware extortion maps to Organized Crime; unauthorized abuse of legitimate internal credentials maps to a Malicious Insider; and unapproved enterprise software adoption driven by operational convenience maps to Shadow IT.

Step-by-Step Solution

1
Analyze the attributes of the first incident narrative.
Identified zero-day firmware exploits, 18-month covert persistence, geopolitical intelligence targets, and extreme funding/sophistication.
These characteristics uniquely align with Nation-State / APT actors who prioritize long-term strategic espionage over direct monetary profit.
2
Evaluate the motivation and vector of the second incident narrative.
Identified double-extortion ransomware, purchased underground credentials, and cryptocurrency extortion demands.
Financially motivated extortion operations utilizing illicit credential marketplaces are signature indicators of Organized Crime.
3
Examine the access mechanisms and intent of the third incident narrative.
Identified legitimate elevated access rights, deliberate evasion of internal monitoring, and exfiltration prior to resignation.
Abuse of authorized access privileges by trusted personnel to steal proprietary assets constitutes a Malicious Insider threat.
4
Assess the intent and authorization level of the fourth incident narrative.
Identified unauthorized adoption of a third-party cloud service by internal staff to fulfill operational duties, introducing exposure.
Unapproved tech adoption by staff without security oversight is classified as Shadow IT.

Key Concept

Threat Actor Classification and Attribute Mapping
Rate this question