Soru

Zorluk: OrtaThreat Actors, Attributes, and Attack Vectors

A threat intelligence team at a global maritime logistics provider is investigating an intrusion into their vessel tracking and scheduling infrastructure. The investigation reveals that an Advanced Persistent Threat (APT) group maintained continuous, undetected access for nine months after obtaining valid third-party vendor API credentials. Forensic analysis indicates the threat actor deployed proprietary, custom-built malware operating exclusively in volatile memory to conduct long-term intelligence gathering. Which TWO of the following attributes and attack vectors typically characterize this specific category of threat actor in contrast to casual hacktivists or script kiddies?

  1. High technical sophistication manifested through custom, fileless memory malware engineered to bypass endpoint defensesCevap
  2. Substantial financial and operational resources enabling long-term persistence and stealthy cyber espionageCevap
  3. C
    Ideological motivation seeking rapid, public website defacement to gain maximum media publicity
  4. D
    Exclusive reliance on automated vulnerability scanners and unpatched public exploit scripts

Cevap

The threat actor described is characterized by high technical sophistication utilizing custom in-memory malware and substantial financial and operational resources enabling long-term persistence.
The correct selections accurately identify nation-state APT attributes: high technical sophistication demonstrated by custom fileless in-memory malware and extensive resource funding supporting prolonged, stealthy cyber espionage.

Adım Adım Çözüm

1
Analyze the incident scenario indicators
Identified long-term presence (nine months), proprietary memory-only malware, and third-party vendor credential abuse, indicating a nation-state Advanced Persistent Threat (APT).
Threat actor categorization relies on observing intent, capability, sophistication, funding, and attack vectors.
2
Evaluate capability and sophistication characteristics
Developing custom fileless payloads requires high technical sophistication, distinguishing APTs from lower-skilled actors.
Script kiddies and low-tier actors rely on known, off-the-shelf exploit scripts rather than custom memory malware.
3
Evaluate resource levels and motivation attributes
Sustaining a multi-month stealthy cyber espionage campaign requires extensive resource backing and long-term strategic intent.
Hacktivists typically seek short-term public disruption for awareness, whereas nation-states fund stealthy, persistent surveillance.

Anahtar Kavram

Threat Actor Attributes and Attack Vectors
Bu soruyu puanla