A cybersecurity incident response team at a global logistics and supply chain enterprise is analyzing four distinct security events across their logistics automation infrastructure. Match each security event description on the left with the most likely threat actor profile on the right.
- An unauthorized modification to automated warehouse software code committed outside business hours using valid credentials belonging to a recently demoted senior developer.Insider Threat (Malicious User)
- A sophisticated zero-day exploit targeting core BGP routing infrastructure, combined with custom multi-stage malware designed to observe long-term supply routing data without altering operations.Nation-State / Advanced Persistent Threat (APT)
- A widespread double-extortion ransomware attack targeting regional dispatch workstations, coupled with demands for cryptocurrency payment to prevent public release of stolen logistics data.Organized Crime Syndicate
- A distributed denial-of-service (DDoS) campaign targeting customer tracking portals accompanied by a public manifesto protesting corporate environmental policies.Hacktivist Collective
Answer
Event 1 matches Insider Threat (Malicious User); Event 2 matches Nation-State / APT; Event 3 matches Organized Crime Syndicate; Event 4 matches Hacktivist Collective.
Each event corresponds to key threat actor attributes: malicious code alterations using demoted employee credentials reflect an insider threat; highly covert zero-day exploitation for espionage indicates a nation-state actor; double-extortion ransomware for monetary gain defines organized crime; and ideologically motivated disruption targeting tracking portals highlights hacktivism.
Step-by-Step Solution
Key Concept
Threat Actor Classification, Attributes, and Motivations