click below
click below
Normal Size Small Size show me how
Threat Actors
Section 3
| Question | Answer |
|---|---|
| threat actor | An individual or entity, responsible for incidents that impact security and data protection |
| Why threat actors do what they do? | data exfiltration, blackmail, espionage, service disruption, financial gain, philosophical or political beliefs, ethical reasons, revenge, war, disruption or chaos |
| threat actor attributes | Specific characteristics or properties that define and differentiate various threat actors from one another |
| types of threat actors | Unskilled attackers, hacktivists, organized crime, nation- state actors, insider threats |
| unskilled attackers | Individuals with limited technical expertise who use readily available tools like downloaded scripts or exploits to carry out attacks |
| hacktivists | Cyber attackers, who carry out their activities driven by political, social, environmental ideologies, who often want to draw attention to a specific cause |
| organized crime | Well-structured groups that execute cyberattacks for financial gain, usually through methods like ransomware, identity theft, or credit card fraud |
| nation-state actors | Highly skilled attackers that are sponsored by governments to carry out cyber espionage, sabotage, or cyber warfare against other nation states or specific targets in a variety of industries |
| insider threats | Security threat that originate from within the organization (employee revenge, lazy staff) |
| Shadow IT | IT systems, devices, software, applications, and services that are management utilized without explicit organizational approval |
| How to outsmart threat actors | honeypots, honeynets, honeyfiles, honeytokens |
| honeypots | Decoy systems or servers designed to attract and deceive potential attackers, simulating real-world IT assets to study their techniques |
| honeynets | Create an entire network of decoy systems to observe complex, multi stage attacks |
| honeyfiles | Decoy files placed within systems to detect unauthorized access or data breaches |
| honeytokens | Fake pieces of data, like a fabricated user credential, inserted into databases or systems to alert administrators when they are accessed or used |
| data exfiltration | The unauthorized transfer of data from a computer. (IP, PII, trade secrets. Sell it on the dark web, using it for identity theft, leveraging it for a competitive advantage |
| financial gain | Of the most common motivations for cyber criminals. Ransomware attacks, banking trojans |
| blackmail | The attacker obtains sensitive or compromising information about an individual or an organization and threatens to release this information to the public unless certain demands are meant (ransomware, doxxing, sextortion) |
| service disruption | Often achieved by conducting a disrupted denial of service (DDos) attack to overwhelm a network, service, or server with excessive amounts of traffic so that it becomes unavailable to its normal users |
| threat actor | An individual or entity, responsible for incidents that impact security and data protection |
| Why threat actors do what they do? | data exfiltration, blackmail, espionage, service disruption, financial gain, philosophical or political beliefs, ethical reasons, revenge, war, disruption or chaos |
| threat actor attributes | Specific characteristics or properties that define and differentiate various threat actors from one another |
| types of threat actors | Unskilled attackers, hacktivists, organized crime, nation- state actors, insider threats |
| unskilled attackers | Individuals with limited technical expertise who use readily available tools like downloaded scripts or exploits to carry out attacks |
| hacktivists | Cyber attackers, who carry out their activities driven by political, social, environmental ideologies, who often want to draw attention to a specific cause |
| organized crime | Well-structured groups that execute cyberattacks for financial gain, usually through methods like ransomware, identity theft, or credit card fraud |
| nation-state actors | Highly skilled attackers that are sponsored by governments to carry out cyber espionage, sabotage, or cyber warfare against other nation states or specific targets in a variety of industries |
| insider threats | Security threat that originate from within the organization (employee revenge, lazy staff) |
| Shadow IT | IT systems, devices, software, applications, and services that are management utilized without explicit organizational approval |
| How to outsmart threat actors | honeypots, honeynets, honeyfiles, honeytokens |
| honeypots | Decoy systems or servers designed to attract and deceive potential attackers, simulating real-world IT assets to study their techniques |
| honeynets | Create an entire network of decoy systems to observe complex, multi stage attacks |
| honeyfiles | Decoy files placed within systems to detect unauthorized access or data breaches |
| honeytokens | Fake pieces of data, like a fabricated user credential, inserted into databases or systems to alert administrators when they are accessed or used |
| data exfiltration | The unauthorized transfer of data from a computer. (IP, PII, trade secrets. Sell it on the dark web, using it for identity theft, leveraging it for a competitive advantage |
| financial gain | Of the most common motivations for cyber criminals. Ransomware attacks, banking trojans |
| blackmail | The attacker obtains sensitive or compromising information about an individual or an organization and threatens to release this information to the public unless certain demands are meant (ransomware, doxxing, sextortion) |
| service disruption | Often achieved by conducting a disrupted denial of service (DDos) attack to overwhelm a network, service, or server with excessive amounts of traffic so that it becomes unavailable to its normal users |
| Philosophical or political beliefs | Individuals or groups use hacking to promote a political agenda, social change, or to protest against orgethanizations they perceive as unethical (website defacement, data leaks). media industry, politics, financial institutions |
| Ethical reasons | Ethical hackers, also known as authorized hackers are motivated by a desire to improve security |
| Revenge | An employee who is disgruntled, or one who has recently been fired or laid off, might want to harm their current or former employer, by causing a data breach, disrupting services, or leaking sensitive information |
| disruption or chaos | These actors, often referred to as unauthorized hackers, engage in malicious activities for the thrill of it, to challenge their skills, or simply to cause harm |
| espionage | Involves spying on individuals, organizations, or nations to gather sensitive or classified information. |
| War | Cyberattacks have been increasingly become a tool for nations to attack each other both on and off the battlefield |
| threat actor attributes | internal vs. external, resources and funding, level of sophistication and capability |
| internal threat actors | Individuals or entities within an organization who pose a threat to its security |
| external threat actors | individuals or groups outside an organization who attempt to breach its cybersecurity defenses. They use malware, social engineering to gain unauthorized access. |
| resources and funding | tools, skills, and personnel at the disposal of a given threat actor |
| level of sophistication and capability | Refers to their technical skill, the complexity of the tools and techniques they use, and their ability to evade detection and other countermeasures |
| Unskilled Attackers | An individual who lacks the technical knowledge to develop their own hacking tools or exploits |
| Hacktivists | Individuals or groups that use their technological skills to promote a cause or drive social change instead of for a personal game. Achieve ideological or political beliefs. |
| What techniques do hacktivists use? | Website defacement, DDOS attack, doxing, leaking of sensitive data |
| Website defacement | Electronic grafitti |
| DDOS attack | Denial of service attack. Overwhelm victims system or networks so they cannot be accessed by businesses or users. |
| Doxing | Public release private information about an individual or organization |
| organized cyber crime groups | sophisticated and well-structured entities that leverage resources and technical skills for illicit gain |
| organized crime skills | custom malware, ransomware, sophisticated phishing campaigns |
| organized crime common exploits | cryptocurrencies, dark web, cellular collection devices |
| organized crime various illicit activities | data breaches, identity theft, online fraud, ransomware attacks |
| nation state actors | Groups that are sponsored by a government to conduct cyber operations against other nations, organizations, or individuals |
| False flag attack | Attack that is orchestrated in such a way that it appears to originate from a different source or group |
| nation state actors possess what advanced techniques? | Creating custom malware, using zero data exploits, becoming an advanced persistent threat |
| Advanced persistent threat | Term that used to be used synonymously with a nation-state actor because of their long-term persistence and stuff |
| what motivates nation state actors? | government funded operations. Gathering intelligence, disrupting, critical infrastructure, influencing, political processes, espionage |
| Stuxnet worm | Sophisticated piece of malware that was designed to sabotage the Iranian government nuclear program |
| Insider threats | Security threats that originate from within the organization |
| Shadow IT | The use of information, tech technology systems, devices, software, applications, and services without explicit organizational approval (managed outside of and without the knowledge of the IT department). can lead to a lack of standards. |
| What can shadow IT use? | Use of personal devices for work purposes, installation of unapproved software, use of cloud services that have not been approved by the organization |
| Why does shadow IT exist? | organization's security posture is set too high or too complex for business operations to occur without being negatively affected |
| Threat vectors | The means or pathway by which an attacker can gain unauthorized access to a computer or network to deliver a malicious payload or carry out and unwanted action |
| attack surface | Encompasses all the various points, where an unauthorized user can try to enter data to or extract data from an environment |
| How to minimize attack surface? | Restricting access, removing unnecessary software, disabling, unused protocols |
| Threats vectors | Messages, images, files, voicemails, removable devices, unsecured networks |
| messages | threats delivered via email, simple message service or SMS text messaging or other forms of instant messaging |
| images | Embedding of malicious code inside of an image file by the threat actor |
| voice calls | Use voice calls to trick victims into revealing their sensitive information |
| Removable devices | threats delivered via removable device devices, such as USB |
| unsecure networks | The lack of appropriate security measures to protect networks |
| BlueSmack | Targets Bluetooth enabled device devices by sending a specially crafted logical link control and adaptation protocol packet to a target device |
| How to outsmart threat actors? | honeypots, honeynets, honeyfiles, honeytokens |
| tactics, techniques, and procedures (TTPs) | Specific methods and patterns of activities or behaviors associated with a particular threat actor or group of threat actors |
| deceptive and disruption technologies | Designed to mislead, confuse, and divert attackers from critical assets, while simultaneously detecting a neutralizing threats |
| honeynet | create a more complex system that is designed to mimic an entire network of systems, including serves, routers, and switches |
| honeypots | used against insider threats to detect internal fraud, snooping, and malpractice |
| what types of files can you create with honeypots | word-processing, spreadsheets, presentation files, images, database files, executables |
| Bogus DNS | Fake DNS entries introduced into a system DNS server |
| Decoy directories | Fake folders and files placed within a system storage |
| Dynamic Page generation | Used in websites to present ever-changing content to web crawlers to confuse and slow down the threat actor |
| Port triggering | Security mechanism where specific services or ports on a network device remain closed until a specific outbound traffic pattern is detected |
| Fake telemetry data | Systems can respond to an attackers network scan attempt by sending out fake telemetry or network data |