
Having a better understanding of what types of attackers are out there and what drives their impetus to mount attacks against cyber targets will enable cybersecurity professionals to better equip themselves with the necessary information to inform, budget, equip and train their organizations to protect themselves from a cyber-attack. While this is not an all-inclusive list, it is a sampling of some of the common threat vectors that are out there that wish to do harm or exploit your resources for personal or professional gain. Let’s take a peek at who some of these cyber threats are:
Nation-State Actors
Nation state actors are government sponsored groups that hack cyber targets in order to gain illegal access to foreign networks of other governments or commercial industries in order to conduct espionage, damage/destroy and/or modify information. These State-sponsored hackers are well equipped and funded and generally follow the orders of the Nation-State. Some high profile Nation-State threats include China’s People’s Liberation Army (PLA), Unit 61398: the Cyber Arm of the PLA, which have been carrying out cyber-attacks all over the world since around 1999 to present, with the most notable recent event being the Equifax Data Breach which involved hacking into Equifax and “exfiltrating” sensitive data as part of a massive heist that also included stealing trade secrets, though the Chinese Communist Party denied these claims.
Another Nation-State Actor of significance is Russian Federation’s Glavnoje Razvedyvatel’noje Upravlenije (GRU), the Russian equivalent of the CIA. The GRU has been implicated in numerous cyber-attacks in the U.S., France, Germany, and Ukraine to name a few. The GRU’s cyber-attack methodology includes espionage, Disruption Operations i.e. DDOS Attacks, Psychological Operation (PSYOPS) (election interference as an example) and attacks against critical infrastructure. The most recent notable attack is the Solarwinds breach, an extremely sophisticated supply chain attack that is still being fully examined as the cyber-body count from this elaborate hack continues to rise.
Hackers-for-Hire
Groups of hackers have banded together and decided to monetize their abilities to provide Hacking-as-a-Service (HaaS) that can be shopped and purchased on the Dark Web with crypto-currency like Bitcoin. Hacking markets have existed in the Dark Web for some time but they have now evolved into a full-fledged marketplace, complete with an ecosystem that supports the business of cybercrime. Hacking marketplaces advertise to people looking to outsource hacking, malware, cyber-crime acts, and the actual hackers; hackers compete amongst each other to provide ‘satisfactory’ services to their ’employers’ in hopes of return business and expansion of their hacking services.
CryptoJackers
This a new phenomenon that has risen from the cryptocurrency boom. To understand the motivation on a cryptoJacker, you need to understand the concept of blockchain technology. To put in simple terms, blockchain banking is a non-centralized way to managing virtual currency while using “miners” as independent “ledgers” to interconnect and track all of the transactions. Miners collect a fee for each transaction, and this has caused a huge boom in individuals and Nation-States (like China) to capitalize on this and build out HUGE datacenters filled to the brim with tiny computers dedicated to the task of cryptomining. Where the CryptoJacker comes in is they don’t want to pay for electricity or computing resources so they set up web sites or phishing scams to hook into unsuspecting people/companies’ computers and leverage them as crypto miners, turning the unsuspecting user’s computer into a bastion host for potential illicit activity as well as a means to hijack computing resources.
Hacktivists
Hacktivists are defined as a person or group of people who gain unauthorized access to computer files or networks in order to further social or political ends. Common targets for hacktivists include government agencies, multinational corporations, or any other entity perceived as ‘bad’ or ‘wrong’ by the hacktivist. The notion of hacktivism was inspired by an individual’s or group’s perception of what they consider to be ‘wrong’ or ‘unjust’ and hence incentivizes them to do something about it. Motivations include revenge, political or social incentives, ideology, protesting, embarrass or expose an organization or individual i.e. “Doxxing”, or just plain old vandalism. Cult of the Dead Cow, Anonymous & LulzSec along with individuals such as “The Jester”, Jacob Appelbaum and Ashley Manning are all examples of notable hacktivists.
Botnet Herders
Botnet Herders are hackers who use automated techniques to scan specific network ranges and find vulnerable systems, such as machines without current security patches, and then install a “bot” program (malware). The infected machine then becomes one of millions of “zombies” in a botnet and responds to C2 commands given by the Herder. This is usually conducted from an Internet Relay Chat (IRC) channel like the old mIRC application. The Conflicker virus is an example of a bot program delivered as a payload from the Conflicker virus infection. Botnet Herders usually use pseudonyms to keep themselves anonymous, and generally use proxy servers, and dummy accounts to obfuscate their true source IP address. If you take a look at the Kaspersky DDoS Dashboard, you can see though, where the lion’s share of these attacks are sourced from and where they are vectored to.
There are an estimated 20 and 30 billion Internet-connected devices and many people are familiar with computers, tablets, smartphones, and wireless Internet. Now other devices, like televisions, home security cameras, and even refrigerators, connect to the Internet; known as the Internet of Things (IOT) which means more attack vectors and a gigantic “attack surface” for hackers. As such there are a number of avenues to take in order to mitigate attacks from these attackers mentioned above. Stay tuned for more advice on some best practices that you can so to secure yourself from unwanted hacking.
![]()
Share this:
- Print (Opens in new window) Print
- Share on X (Opens in new window) X
- Share on Facebook (Opens in new window) Facebook
- Share on Reddit (Opens in new window) Reddit
- Share on LinkedIn (Opens in new window) LinkedIn
- Share on Pinterest (Opens in new window) Pinterest
- Share on Tumblr (Opens in new window) Tumblr