Skip to content
All lessons
Objective 2.1Threats & Vulnerabilities· 4 min read

Threat Actors and Motivations

Compare and contrast common threat actors and motivations

What you will learn

  • Tell the six actors apart by resources and capability, not by name alone.
  • Match each motivation to the actor it typically belongs to: espionage, financial gain, or a political stance.
  • Understand why an insider threat outranks a technically stronger outside attacker.
  • Recognise shadow IT — it is on the list, and it is not an attacker.

This objective does not ask for definitions; it asks for inference. The question describes an attack — how long it ran, what tools it used, what it went after — and waits for you to name the likely actor. Three things decide it: how many resources they have, how much skill, and what they want.

The six actors

Nation-stateA state, or a group acting for one. The highest resources and patience: campaigns running for months without noise, and purpose-built tooling. Usually described as an APT.
Unskilled attackerRuns ready-made tools written by someone else and does not understand how they work. The lowest resources and skill — though the damage can still be large, because the tool is capable.
HacktivistDriven by a political or social stance, not money. Tends toward the visible: website defacement, service disruption, leaking documents to embarrass an organisation.
Insider threatSomeone who already has legitimate access: an employee or a contractor. May be deliberate or merely careless. The danger is that they need to break into nothing.
Organized crimeAn organised group after money. Professional and funded, run like a business — ransomware is its best-known model.
Shadow ITSystems and services staff use without IT's knowledge. Not an attacker: it is attack surface nobody knows exists, so nothing patches or monitors it.

Shadow IT is on the actor list and is not an actor

CompTIA lists it among the actors, yet it is not a person attacking you. An employee subscribing to a cloud storage service to get work done faster intends no harm — but has created a door outside every control you have. If a question describes a tool a team uses without formal approval, the answer is shadow IT however much more "attacking" the other options look.

Nation-state vs organised crime

Nation-stateOrganised crime
MotiveEspionage, strategic disruption, warMoney before anything
PatienceMonths or years; staying hidden is itself a goalThe fastest possible return
ToolingPurpose-built, including zero-daysMature tools bought and rented
Visible impactThere may be nothing visible at allDeliberately visible — pressure is part of the model

Motivations

Data exfiltrationStealing data and moving it out.
EspionageGathering information for a state or a competitor. The goal is knowledge, not money.
Financial gainRansom, fraud, selling data.
Service disruptionTaking the service down is the goal — nothing is stolen.
Philosophical / politicalThe hacktivist's motive: making a point.
RevengeCommon in insider threats, especially after a termination.

Real-world example: the description names the actor

A manufacturer discovers unauthorised access that ran for eleven months. Nothing was encrypted, no money was demanded, no service went down, and what left was design documents for a product still in development. The tooling matched no known malware family. Read the signals: the long dwell time means resources and patience; the absence of a money demand rules out organised crime; the absence of noise rules out a hacktivist, who wants to be seen; the bespoke tooling rules out an unskilled attacker. What remains is a state-backed actor whose motive is industrial espionage.

Three questions settle the actor

How long did it run? Long and quiet = nation-state. What was demanded? Money = organised crime. What was announced? A message or defacement = hacktivist. And if nothing was broken into because the access was already legitimate = insider threat.

What matters on the exam

  • "Ran for months undetected" and "unknown tooling" point to a state-backed actor, even when the question never says APT.
  • An insider threat breaks into nothing. If the question says the actor already had the access, stop looking for a vulnerability.
  • An unskilled attacker is identified by their tools, not their impact: the damage can be large and the tool still not theirs.
  • Watch the motive/actor swap. The question may hand you the motive and ask for the actor, or the reverse.

Quick check

Answer in your head first, then reveal.

  1. A group takes a ministry's website down and publishes a statement explaining their objection. Which actor, which motive?Reveal the answer

    A hacktivist, with a political or philosophical motive. The evidence: the act is announced and meant to be seen, and there is no money demand.

  2. Why is an insider threat dangerous even when less skilled than an outside attacker?Reveal the answer

    Because most controls are built to keep people out, and they are already in. They need no vulnerability and no privilege escalation, and their activity looks like their job, so it is hard to single out.

  3. A marketing team uses a cloud file-sharing tool IT never approved. What is the classification?Reveal the answer

    Shadow IT. No malicious intent, but the data now sits somewhere unmonitored, unpatched and outside every control — attack surface nobody knows exists.

  4. A ransomware attack shuts down a hospital and demands a sum in cryptocurrency. Most likely actor?Reveal the answer

    Organised crime, motivated by financial gain. The explicit money demand and the openly applied pressure separate it from quiet espionage.

Sign in to track your progress on this topic.

Your next step

Read the lesson, then mark it complete