TechKnowSurge
NIST NICE K0833 NIST NICE K0684 ISC2 CC 1.1 Cisco CCST Cybersecurity 1.2 NIST NICE K1066 NIST CSF ID.RA-03
VideoSecurityFree

Threats - Threat Agents

Threat agents and threat actors are individuals or entities that intend to cause harm to an organization, and understanding who they are, what drives them, and how they operate is foundational to building an effective cybersecurity defense.

Complete this video to capture a CTF flag worth 1 point.

About this video

A threat agent or threat actor is any individual or entity with the intent to cause harm to an organization or its assets. While some sources draw a distinction between the two terms, the difference is minor enough that they are widely treated as interchangeable in practice. Understanding threat agents means going beyond simply knowing that attacks happen and examining the characteristics that shape how, why, and from where those attacks originate. Threat agents differ across several key attributes: whether they are internal or external to the organization, the level of resources and funding behind them, and their degree of technical sophistication, ranging from unskilled actors running pre-built scripts to highly capable operators with deep knowledge of vulnerabilities and network architecture. Their motivations are equally varied and include financial gain, information theft and espionage, a desire to drive political or philosophical change, self-gratification through notoriety or intellectual challenge, and retribution against specific targets or organizations. Insider threats and shadow IT, where employees use unsanctioned tools or services outside of IT oversight, represent particularly common and underestimated sources of organizational risk. Threat agents do not always act alone. Sponsorship from nation-states, organized crime operations, terrorist groups, or rival corporations significantly increases both the resources and persistence an attacker can bring to bear. Among the most serious threat categories is the advanced persistent threat, or APT, which describes a highly skilled actor who has already gained access to a network and continues to operate inside it undetected over an extended period. Other defined types include hackers who gain unauthorized access through computer systems, script kiddies who rely on automated tools with limited technical knowledge, vulnerability brokers who exploit or sell discovered weaknesses, and hacktivists who attack systems in pursuit of social or political goals. Recognizing these distinctions helps organizations prioritize their defenses and allocate resources where the risk is greatest.

What you'll learn

What's covered

Threat Agents & Actors

Aligned to

NIST NICE
K0833 Knowledge of cyberattack actor characteristics
K0684 Knowledge of cybersecurity threat characteristics
K1066 Knowledge of threat behaviors
ISC2 CC
1.1 Understand cybersecurity concepts
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
NIST CSF
ID.RA-03 Internal and external threats to the organization are identified and recorded.

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Advanced Persistent Threat
APT
Advanced Persistent Threat describes a sophisticated, long-term intrusion campaign in which a threat actor maintains unauthorized access to a target network over an extended period to steal data, conduct espionage, or pre-position for future attacks.
Hacktivist
A threat actor who conducts hacking activities to promote political, ideological, or social change.
Script Kiddie
An unskilled threat actor who uses pre-written scripts or tools to attempt unauthorized access without deep technical knowledge.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Threat
Any potential event or action that could cause harm to a system, network, or organization.

Topics

Threat Agents Insider Threats Advanced Persistent Threats Hacktivists Threat Actor Motivations Cybersecurity

Transcript

When we're trying to protect our cybersecurity domain, it's helpful to keep in mind who might be attacking it and what their reasoning might be. Then we can better understand how to protect our network.

Defining a Threat Agent

One thing to note is that different resources have different information out there, and that comes into play when it's talking about definitions or groupings or the way they portray information. It's no different with this threat agent versus threat actor. There are some resources out there that define them as two different things and explain the difference, although it's very slight. There are some resources out there that say it's the same thing, and there are some resources out there that don't even address it. For our purposes, it doesn't really matter. They're close enough to the same thing that we're just going to define both of them as the individual or entity that has the intent to do harm. So there you go: a threat agent or actor is an individual or entity that has the intent to do harm.

Attributes of a Threat Agent

So why would a threat agent want to do harm? There's lots of reasons, and there's other attributes that we can associate with a threat agent as well. Let's take a look at some of those.

First of all, what is the relationship of the threat agent to the organization? For instance, let's say it is somebody trying to hack an organization, or trying to commit espionage against the corporation, or trying to do something to an organization. What are they? Are they somebody who is internal or external? Are they an employee or some other association that's actually within the company, or is it external? Do they have no association with the company — they just happen to choose this organization and go after it?

There's also a level of resource funding. Each one of these hackers or threat agents will have a certain amount of resources available to them to be able to leverage to get into this organization, to be able to start hacking the organization or try to commit some other fraud against this organization. So what level is it? Is it something that's really small and they really don't have a lot of resource or funding to really do it — they're just doing it for fun, or they're just doing it with a minimal budget? Or do they have quite a bit of resource and funding that's behind them?

There's also a level of sophistication. For these threat agents, some of them don't really know all that much and they're just kind of dabbling. They're just trying to see what the low-hanging fruit is, where others will have a lot more sophistication, where they're actually in there doing some really complex work and really have a deep understanding around cybersecurity and different vulnerabilities.

Then you have the intention or motivation. We're going to get pretty deep into intention and motivation: what is their reasoning behind trying to leverage this company, or trying to go after another person, or whatever they're trying to do? What is their reasoning, their intention, their motivation behind that? For instance, it could be just monetary — they could be going after some sort of money — or it could be information.

And then finally, sponsorships. Is there anybody that's standing behind them? It's not just the hacker, it's not just the threat agent, it's not just the single entity — is there more people that are actually sponsoring this, like a government agency sponsoring? We'll talk about each one of these areas in a little more depth.

Motivations

So what would be the motivation of a threat agent to do what they're doing? It could be financial. It could be for information. It could be because they want to see a change. It could be for self-gratification. It could be for retribution. Let's take a look at a few of these.

First of all, financial. That's pretty straightforward — that just means money. Information is pretty straightforward as well, although if it's information, they probably want to use that information to make some sort of change or for some sort of financial gain. So it's probably not the underlying reason; they're just getting the information for some other underlying reason. A couple of things to keep in mind with this is data exfiltration. Data exfiltration is the idea of stealing data. Also, espionage could count — this is one of the things that espionage is for, to steal information. That's like spies, and it could be a government spy or government espionage, or it could be corporate espionage, going into a competitor and trying to find out information about a competitor.

A big motivation why certain hackers and threat agents do what they do is because they want to see some sort of change. Maybe it's some sort of philosophical change, political, ethical. Cyber terrorism could fall under this; cyber warfare could fall under this. There is some big value difference that they want to see a change in, and so this is what they're going after. This is what they're trying to make happen.

Another thing would be self-gratification. There are some that just get this high off of doing what they do, such as curiosity — they have a curiosity and want to figure things out. Maybe it's intellectually challenging. Maybe by attacking something like a government website or something big, they get a certain amount of confidence and pride and ego out of it, some sort of power. They possibly get some sort of notoriety or fame or peer recognition out of it. So there's a lot of different reasons that might go into why somebody might feel like, "Oh, this is exhilarating, this is something that I want to continue to do because I get excited about it."

Somebody could also have just retribution. This could be something specific, like they're doing retribution against a specific person or a company, or it could be just in general that they've been dealt a bad hand in life and now they want to take it out on everyone. So this looks like maybe they just have a vindictive personality. Maybe they just want to create disruption and chaos and they get a high off of that. Maybe they're just a bully — I think of a bully when I think of this. Maybe they're out for some sort of revenge.

And then I saw one of the sites mention testing. I don't know that this is necessarily a threat agent. This is one of the motivations, that we do testing on our network to make sure that they're secure and everything. I thought I'd throw that in there, but I don't know that a threat agent would necessarily want to be doing testing — although maybe if they see themselves as a white hat or a gray hat hacker, maybe that would fall under that. And then there is something called shadow IT. Maybe somebody just wants to get some work done. We're going to talk more about shadow IT, so I'm not going to get too in depth into that on this slide.

Sponsors

A lot of times we think of somebody on their own, in their bedroom or in their office, sitting there trying to hack the government or hack something. That is out there, but actually what's becoming more prevalent is some being sponsored by somebody. It could be a state or nation. It could be organized crime — this is a huge one right now with scam artists, that there's whole companies out there that are calling up people and doing scams and stuff, and they're making tons of money off of it. There's other groups and organizations, like cyber terrorism that happens. And then there's also corporations that will actually commit corporate espionage or attack another corporation to try to leverage information or try to leverage it against something, to get a competitive advantage. There's lots of reasons for them to do it.

Types of Threat Agents

There are some terms around threat agents that didn't quite fit into my other slides, so let's go over those now.

First of all is a hacker. A hacker is a type of threat agent, but the definition is a little different. These are two different things; they're not the same thing. A threat agent is just a threat to the company or organization, versus a hacker is specifically somebody who is using a computer to gain unauthorized access. So that's a hacker — it's a little more specific than just a regular threat agent.

Another thing that didn't quite fit is blackmail. People will use things like information to blackmail somebody. That means that they have some sort of threat to them and say, "Well, I'm going to release this information, or I'm going to do this thing, if you don't do" — and then fill in the blank. So they're trying to leverage it to gain something out of it.

Then we have this insider threat. The idea behind an insider threat is somebody who has some sort of authorized access into the company or organization and they're leveraging it for whatever it is that they want to leverage it for. So think of maybe they're spying for another corporation or another government agency. Maybe they're disgruntled and they just want to take out revenge, and so they're doing revenge. Or perhaps it's shadow IT.

Shadow IT

Shadow IT is probably the most prevalent threat that I've seen and encountered in the organizations that I worked with. It's probably the thing that's come up the most and the thing I've seen the most.

So what is shadow IT? Shadow IT is the idea that the people of a company or organization, the insiders, are doing their own thing without IT knowing about it. This is real prevalent, and there's a reason why it's real prevalent: because a lot of times when you go through a process, it slows things down. And there are people within the company that don't want that to be slowed down. They don't want barriers. They want to do their work and they want to make it happen. To a certain degree I can sympathize with that. I can understand that they want to do their work, and there are times when they have to go through an official process and it becomes problematic. But those processes are in place for a reason. So really the reason why shadow IT is so prevalent is because people want to get things done. The problem is that they don't get things done right, and it's like rolling the dice.

A good example of this is that somebody were to go out and set up a free account for some sort of software that's out there, because there's a lot of premium software out there, and they upload some company data into it and they've got it shared out to maybe a couple of customers. So there's this information that's out there that's not on an IT approved system, and then that person leaves the company, and at the same time they are the only ones that had access to this data. Now no one knows about the data, or they don't know how to get to the data, or the data goes offline and then customers don't have it. There's a whole host of reasons why this becomes very problematic. It's not going to become problematic every time — it's like rolling a dice once again — but when it does become problematic, it can be really devastating to the company.

Hacker Types

There are other resources out there that specify other colored hats out there, depending on what the motivation and goals of the hacker is. I'm not going to get into all of that. This really drives home the point of what we're trying to get at, but just know that there are some sites out there that will go a little more granular into defining this.

A few last terms here that we'll cover. One of them is a script kiddie. The idea behind a script kiddie is somebody who's just running scripts out there to find leverages and to break into things. Usually they're very unskilled and they are just trying to hack into things and they're not very knowledgeable, but they do know how to find some scripts and run some scripts against the environment to try to leverage things and break into it.

Another one is a vulnerability broker. That's somebody who's trying to find vulnerabilities and then sell those vulnerabilities either back to the company, or they're trying to leverage something to get money out of the situation by finding these vulnerabilities.

And then finally, we've got an activist. The activist is those who want to promote some sort of change, and they're hacking to promote that type of change.

Advanced Persistent Threats

One of the most dangerous types of threats there are would be an advanced persistent threat, or an APT. The concept behind this is two parts. Part of it is the advanced part: they are not these script kiddies, they're not the unskilled. Quite the opposite — they are very skilled. They fall on the other side of the spectrum here, where they fall under a very skilled attack. So they really know what they're doing.

The persistent part can be a little confusing. Persistent sounds like they're just persistently attacking, like they have not intruded on your system yet. But that's not the case. Persistent means that they've been persistently inside of your network. So what that means is that they've already hacked your network and they're lingering inside of your network. And so you don't always know everything that's exposed inside of your network, because they've been there for a long time. So an advanced persistent threat is somebody who is very skilled, has already hacked your network, and maintains persistence on that network.

Review

We started out by defining what a threat agent is, and that is somebody or an organization that has intent to do harm to our organization or company. Then we talked about some of the attributes that a threat agent may have. Then we got more in depth into what their motivations are and listed out several motivations around that. We talked about if they have sponsors or not. We talked about some different types of threat agents. And then we wrapped things up by talking about a specific type, the hacker, and the types of hackers there are.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →