A threat intelligence team at a global maritime logistics provider is investigating an intrusion into their vessel tracking and scheduling infrastructure. The investigation reveals that an Advanced Persistent Threat (APT) group maintained continuous, undetected access for nine months after obtaining valid third-party vendor API credentials. Forensic analysis indicates the threat actor deployed proprietary, custom-built malware operating exclusively in volatile memory to conduct long-term intelligence gathering. Which TWO of the following attributes and attack vectors typically characterize this specific category of threat actor in contrast to casual hacktivists or script kiddies?
- High technical sophistication manifested through custom, fileless memory malware engineered to bypass endpoint defensesAnswer
- Substantial financial and operational resources enabling long-term persistence and stealthy cyber espionageAnswer
- CIdeological motivation seeking rapid, public website defacement to gain maximum media publicity
- DExclusive reliance on automated vulnerability scanners and unpatched public exploit scripts
Answer
The threat actor described is characterized by high technical sophistication utilizing custom in-memory malware and substantial financial and operational resources enabling long-term persistence.
The correct selections accurately identify nation-state APT attributes: high technical sophistication demonstrated by custom fileless in-memory malware and extensive resource funding supporting prolonged, stealthy cyber espionage.
Step-by-Step Solution
Key Concept
Threat Actor Attributes and Attack Vectors