Skip to main content

Script-Kiddies

At the most basic level, we encounter script kiddies—inexperienced individuals who use existing tools or exploit kits without a deep understanding of how they work. Their motivation is often curiosity, bragging rights, or low-level mischief. While they pose a relatively low risk compared to more advanced adversaries, their activities can still cause disruption, especially if they stumble upon poorly secured systems. Regarding funding, they normally have access to no real budget and the activity is constrained to some hours of the day, generally not dedicated full-time.

Nation-State

On the other end of the spectrum are Nation-state actors. They work for Governments and generally incur in espionage or sabotage to hinder the ability of other countries to carry out normal activities. These actors possess seemingly unlimited funds, sponsored by the country they work for, paired with the highest level of expertise as they recruit the best performing cybercriminals they can get. They have been responsible for creating Advanced Persistent Threats (APTs) in the past, the most sophisticated malware. APTs operate with long-term objectives and often focus on strategic advantage. They are characterized by stealth, persistence, and the ability to bypass even sophisticated defenses. Nation-state attackers often perform Zero-Day attacks via these APTs. Zero-Day attacks exploit a vulnerability never exploited before, of which there was no previous knowledge, and, as such, often have a devastating impact until the vulnerability is mitigated and the attack is contained. A great example of this is the Stuxnet attack, which compromised an Iranian uranium facility’s SCADA system.

Organized Criminals

In between the two aforementioned categories, lay the rest. Organized Criminals are motivated by financial gain. They engage in activities like ransomware deployment, credit card fraud, identity theft, data trafficking, child sexual abuse material posting and dark web activity. Many operate within organized cybercrime syndicates that function much like businesses, complete with customer service for victims who pay ransoms. Most of them try to remain hidden and go undercover. They have plenty of resources to work with and normally have great expertise in Cybersecurity. They do not hesitate to invest money on their illegal activities, as they think that money makes money.

Hactivists

Hacktivists act out of ideological or political motives. They may deface websites, leak information, or disrupt services to support causes such as environmentalism, human rights, or anti-government sentiment. Hacktivists vary widely in the resources they have access to as well as in the knowledge they have. It could just be a disgruntled employee working alone with little idea of what he is doing, whereas on the other side they can also pose a real threat as has happened with Anonymouse in the past, one of the biggest hacktivists organizations to ever exist. In fact, it is believe that many of the major hackers to ever exist honed their skills as cybersecurity practitioners. As they act for their beliefs, they justify their actions on the greater good. As such, they will risk getting caught and some of them will see that as a badge of honor. Regarding funds the range is as wide as the expertise, and normally is directly associated with the size of the corporation. the more people cooperating for the same cause, the bigger the budget.

Insiders

Insiders are particularly dangerous due to their legitimate access to systems, as they are internal people. They can be malicious (disgruntled employees seeking revenge), negligent (accidentally leaking data), or even unwitting (falling for phishing emails and enabling attackers). They could be of any skill level and could act alone or in small groups. Insiders may be unskilled attackers or very technically skilled. Depending on the role they had on the company, insiders can have significant access to resources, thus, having the potential to cause huge harm to the enterprise.

Competitors

Competitors in the corporate world may resort to unethical practices like espionage to gain business advantages. Though rare and illegal, such threats are real and difficult to detect. They could take advantage of disgruntled employees to perform illegal activities that could give them a competitive advantage in the market. In some cases they look for insider information available on the dark web (a shadowy anonymous network often used for illegal activity), where the way the information was obtained is not important.