Question

Difficulty: MediumThreat Actors, Attributes, and Attack Vectors

A cybersecurity incident response team at a global logistics and supply chain enterprise is analyzing four distinct security events across their logistics automation infrastructure. Match each security event description on the left with the most likely threat actor profile on the right.

  • An unauthorized modification to automated warehouse software code committed outside business hours using valid credentials belonging to a recently demoted senior developer.Insider Threat (Malicious User)
  • A sophisticated zero-day exploit targeting core BGP routing infrastructure, combined with custom multi-stage malware designed to observe long-term supply routing data without altering operations.Nation-State / Advanced Persistent Threat (APT)
  • A widespread double-extortion ransomware attack targeting regional dispatch workstations, coupled with demands for cryptocurrency payment to prevent public release of stolen logistics data.Organized Crime Syndicate
  • A distributed denial-of-service (DDoS) campaign targeting customer tracking portals accompanied by a public manifesto protesting corporate environmental policies.Hacktivist Collective

Answer

Event 1 matches Insider Threat (Malicious User); Event 2 matches Nation-State / APT; Event 3 matches Organized Crime Syndicate; Event 4 matches Hacktivist Collective.
Each event corresponds to key threat actor attributes: malicious code alterations using demoted employee credentials reflect an insider threat; highly covert zero-day exploitation for espionage indicates a nation-state actor; double-extortion ransomware for monetary gain defines organized crime; and ideologically motivated disruption targeting tracking portals highlights hacktivism.

Step-by-Step Solution

1
Analyze the motivation, capability, and attack methods described in each event scenario.
Event 1 shows internal credential misuse after demotion; Event 2 shows highly sophisticated covert espionage; Event 3 shows profit-driven ransomware extortion; Event 4 shows ideologically driven service disruption.
Threat actors are differentiated by their intent, resource level, sophistication, and primary operational goals.
2
Map scenario traits to official threat actor categorizations.
Personal grievance using internal access maps to Insider Threat; state-sponsored espionage maps to Nation-State; financially motivated extortive cybercrime maps to Organized Crime; political protest maps to Hacktivist.
Accurate threat actor identification allows organizations to tailor security controls, threat intelligence matching, and response playbooks.

Key Concept

Threat Actor Classification, Attributes, and Motivations
Rate this question