Skip to content

Threat Actor

Definition

An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction) and by sophistication. Nation-state actors, organised criminal groups, and opportunistic script kiddies each present different risk profiles and require different responses.

Field
Cyber threat intelligence, incident response
Definition
Individual or group responsible for a security incident
Motivations
Financial, espionage, hacktivism, destruction
Sophistication range
Nation-state to opportunistic script kiddie

Common questions

Why does an organisation need to identify the type of threat actor behind an incident?+

Different actor types pursue different objectives and use different levels of persistence, so attribution shapes the response: a financially motivated criminal group may be deterred by raising the cost of the attack, while a nation-state actor pursuing espionage is likely to return regardless of short-term countermeasures.

Is attribution to a specific threat actor usually certain?+

Rarely with full certainty. Analysts assign confidence levels based on overlapping infrastructure, tooling, and behavioural patterns compared to known groups, and attribution can be deliberately muddied by actors reusing or planting another group's tools.

Related terms

Advanced Persistent Threat (APT)
A category of attacker, typically nation-state or state-sponsored, characterised by high technical capability, long dwell times, specific targets, and disciplined operational security....
CSIRT (Computer Security Incident Response Team)
A dedicated team responsible for coordinating the response to confirmed security incidents. The CSIRT manages containment, forensic investigation, communication to stakeholders, and...
Escalation Path
The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Insider Threat
An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
SOC (Security Operations Centre)
A function providing continuous monitoring, alert triage, and early detection of security events. The SOC is the first tier of response: it...
Tactics, Techniques, and Procedures (TTPs)
A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
Threat Intelligence
Processed, analysed information about adversaries, their capabilities, and their current or anticipated activities. Includes strategic intelligence (actor motivations and trends) and tactical...
Threat Vector
The pathway or method a threat actor uses to gain access or cause harm. Examples include phishing email, unpatched software vulnerabilities, compromised...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.