A security operations team investigating an incident at a global maritime logistics enterprise discovers that an unauthorized external entity compromised an edge API endpoint used by a third-party tracking partner. The threat actor utilized legitimate, stolen developer API tokens to gain access. Over an eight-month period, the actor made subtle, highly targeted modifications to cargo manifest metadata to delay specific dual-use technology shipments across international borders. The actor avoided deploying malware, exfiltrating bulk data, or disrupting general operations to evade detection by automated security controls. Based on these observed tactics, techniques, and procedures (TTPs), which threat actor profile and attribute combination is MOST likely responsible for this attack?
- AOrganized crime syndicate motivated by financial gain and leveraging rapid automated exploitation tools
- Nation-state threat actor possessing high sophistication, extensive funding, and long-term geopolitical intentCevap
- CHacktivist collective seeking public ideological disruption using low-sophistication off-the-shelf scripts
- DUnintentional insider threat resulting from shadow IT systems misconfiguring third-party integration controls