During a routine post-incident investigation at a commercial financial auditing firm, security engineers discover an intrusion originating from a compromised third-party software build pipeline. The attack exhibited high technical sophistication, stealthy persistence across multiple network segments, and extensive resource backing, with an operational focus on long-term corporate intelligence gathering rather than immediate financial extortion. Which threat actor profile best aligns with the operational attributes and attack vector observed in this scenario?
- State-sponsored threat groupCevap
- BIdeologically motivated activist group
- CUnapproved internal system deployment
- DNovice opportunistic attacker
Cevap
State-sponsored threat group
State-sponsored threat groups have the high technical capability, funding, and strategic intent necessary to execute complex supply chain compromises for long-term cyber espionage.
Adım Adım Çözüm
Anahtar Kavram
Threat Actor Attributes and Attack Vectors