A security analyst at a municipal emergency dispatch center is investigating a targeted network breach. The adversary gained initial access through compromised supply chain vendor credentials, utilized custom zero-day exploits to maintain persistent access across system reboots, and subtly modified dispatch routing tables without demanding a ransom or exfiltrating data. Threat intelligence reports indicate the threat group operates with state-sponsored backing, high technical sophistication, and extensive financial resources aimed at critical infrastructure disruption. Which of the following threat actor categories best describes the adversary behind this attack?
- Nation-state actorAnswer
- BHacktivist collective
- COrganized crime syndicate
- DScript kiddie
Answer
Nation-state actor
The correct answer is the nation-state actor because the scenario describes state-sponsored backing, custom zero-day development, high financial resources, and stealthy operational disruption of critical public safety infrastructure without a financial motive.
Step-by-Step Solution
Key Concept
Threat Actor Types, Attributes, and Motivations