PDF p.27
In progress
Motivations of Threat Actors
Summary
PDF p.27Threat actors are driven by various motivations, including financial gain, political objectives, and causing chaos. Their attacks can be structured/targeted or unstructured/opportunistic, and they can be either malicious or unintentional.
In plain words
Supplementary — not from your PDFAttackers want different things: money, politics, revenge, or just chaos. Their strategies line up with the CIA triad: stealing data hits confidentiality, disinformation hits integrity, and disruption hits availability.
Detailed explanation
PDF p.27-
Motivation
- Definition: The reason behind a threat actor's attack.
- Types: Greed, curiosity, grievance, etc.
- Characterization: Structured/targeted (e.g., criminal gang stealing data) or unstructured/opportunistic (e.g., unskilled hacker spreading a worm).
-
General Strategies
-
Service Disruption
- Definition: Prevents normal operations of an organization.
- Methods: Attacks on websites, malware blocking access.
- Uses: Chaos, revenge, blackmail, or strategic objectives.
-
Data Exfiltration
- Definition: Unauthorized transfer of valuable information.
- Motivations: Personal use, blackmail, selling to third parties.
-
Disinformation
- Definition: Falsifying trusted resources.
- Methods: Website content changes, fake sites, social media bots.
-
CIA Triad Impact
- Confidentiality: Compromised by data exfiltration.
- Integrity: Attacked by disinformation.
- Availability: Targeted by service disruption.
-
Service Disruption
-
Chaotic Motivations
- Early Internet: Attacks for chaos and credit.
- Modern Use: Political ends, war aims, revenge (e.g., disgruntled employees).
-
Financial Motivations
- Sophistication: Increased opportunities for financial gain.
-
Methods
- Blackmail: Payment to prevent information release.
- Extortion: Payment to stop an attack.
- Fraud: Falsifying records, affecting share prices, promoting schemes.
-
Political Motivations
- Definition: Attacks to bring societal or governance changes.
-
Examples
- Whistleblowing: Ethical concerns.
- Campaign Groups: Disrupting contradictory organizations.
- Nation-States: Espionage, disinformation, service disruption for war aims.
- Commercial Espionage: Companies stealing competitor secrets.
Important terms
taken from the text above- Motivation
- The reason behind a threat actor's attack.
- Characterization
- Structured/targeted (e.g., criminal gang stealing data) or unstructured/opportunistic (e.g., unskilled hacker spreading a worm).
- Service Disruption
- Prevents normal operations of an organization.
- Data Exfiltration
- Unauthorized transfer of valuable information.
- Motivations
- Personal use, blackmail, selling to third parties.
- Disinformation
- Falsifying trusted resources.
- Confidentiality
- Compromised by data exfiltration.
- Integrity
- Attacked by disinformation.
- Availability
- Targeted by service disruption.
- Early Internet
- Attacks for chaos and credit.
- Modern Use
- Political ends, war aims, revenge (e.g., disgruntled employees).
- Sophistication
- Increased opportunities for financial gain.
- Blackmail
- Payment to prevent information release.
- Extortion
- Payment to stop an attack.
- Fraud
- Falsifying records, affecting share prices, promoting schemes.
- Political Motivations
- Attacks to bring societal or governance changes.
- Whistleblowing
- Ethical concerns.
- Campaign Groups
- Disrupting contradictory organizations.
- Nation-States
- Espionage, disinformation, service disruption for war aims.
- Commercial Espionage
- Companies stealing competitor secrets.
Examples & real-world scenarios
Supplementary — not from your PDF- Financial: ransomware demanding payment (extortion).
- Political: leaking documents to embarrass a government.
- Revenge: a fired employee deleting files.
Scenario
A company's website is defaced with a political message and its customer database appears on a leak site the same day. Two strategies are in play (disinformation and data exfiltration), and the motive is likely political.
Common mistakes
Supplementary — not from your PDF- Mixing up blackmail (pay or we release your data) with extortion (pay or the attack continues).
- Forgetting that 'structured vs unstructured' describes how organized the attack is, not how skilled the attacker is.
Practical skills
Supplementary — not from your PDF- Link an attacker's motive to their likely strategy and the CIA property at risk.
What I should remember
Key Points PDF p.27-
Motivation
- Reasons: Greed, curiosity, grievance.
- Types: Structured/targeted, unstructured/opportunistic.
-
General Strategies
- Service Disruption: Prevents normal operations.
- Data Exfiltration: Unauthorized information transfer.
- Disinformation: Falsifies trusted resources.
- CIA Triad: Confidentiality, integrity, availability impacts.
-
Chaotic Motivations
- Early Internet: Chaos and credit.
- Modern Use: Political ends, revenge.
-
Financial Motivations
- Methods: Blackmail, extortion, fraud.
-
Political Motivations
- Examples: Whistleblowing, campaign groups, nation-states.
- Commercial Espionage: Competitor secrets theft.