During an incident investigation at a biotechnology research facility, forensic analysts discover that an adversary gained initial network access through a compromised third-party software supply chain, utilized unpublished zero-day vulnerabilities targeting the underlying virtualization hypervisors, and established covert, out-of-band command-and-control channels to exfiltrate proprietary genomic sequencing intellectual property. The intruder maintained stealthy persistence for over ten months without altering system integrity, deploying ransomware, or publishing defacement material. Which threat actor profile MOST accurately aligns with the observed attributes, capabilities, and attack vector?
- A nation-state actor operating with high sophistication, extensive financial resourcing, and strategic espionage intent.Cevap
- BA hacktivist collective seeking public disruption and ideological exposure of corporate activities.
- CAn opportunistic insider threat utilizing unauthorized shadow IT applications for personal convenience.
- DAn organized crime syndicate focused on immediate financial extortion via widespread ransomware deployment.
Cevap
A nation-state threat actor operating with high sophistication, extensive financial resourcing, and strategic espionage intent.
The correct response identifies a nation-state actor. Advanced attributes such as developing or acquiring zero-day exploits, breaching software supply chains, establishing out-of-band command-and-control, and maintaining multi-month stealthy persistence to steal competitive intellectual property are signature characteristics of state-sponsored threat groups with vast resources and strategic espionage goals.
Adım Adım Çözüm
Anahtar Kavram
Threat Actor Classification and Attribute Identification