PasswordGeeks
Cybersecurity Fundamentals · Lesson 5

Types of Cyber Threat Actors: A Beginner's Guide

Cyber attacks do not come from one single type of attacker. Threat actors have different skills, motivations, resources and targets. This beginner-friendly guide explains six major categories and shows why understanding the attacker matters when building a cybersecurity defense.

Lesson 5 of 9 Module 1 · Introduction to Cybersecurity Includes Quiz
01 · The Basics

What Is a Cyber Threat Actor?

A cyber threat actor is a person, group or organization that can intentionally or unintentionally create a cybersecurity risk.

In security operations, the term is commonly used for people or groups behind malicious cyber activity. Threat actors differ significantly. A beginner using a publicly available tool, a criminal organization running ransomware campaigns, and a state-backed group conducting espionage may all attack computers, but their capabilities and goals are very different.

Understanding those differences helps defenders estimate risk, identify likely attack patterns, and decide which controls are most appropriate.

Cyber threat actor landscape showing six actor categories around a protected organization

Threat Actor Landscape
File: images/cyber-threat-actors-landscape.png — shows attacker categories, motivations and common targets

02 · Think Like a Defender

Motivation, Capability and Target

Before looking at individual categories, remember three questions security teams often ask when assessing a threat:

Why? What does the actor want?
How? What capabilities and techniques can they use?
Who? Which people, systems or organizations are likely targets?

Motivation can include financial gain, ideology, espionage, disruption, revenge, or personal curiosity. Capability can range from basic use of existing tools to highly resourced, long-term operations.

03 · Threat Actor #1

Script Kiddies

01 / SCRIPT KIDDIES

What Are Script Kiddies?

Script kiddie is an informal term for a relatively inexperienced attacker who relies heavily on existing scripts, automated tools, or publicly available exploits rather than developing sophisticated techniques themselves.

MotivationCuriosity, attention, experimentation or mischief
CapabilityUsually low, although tools can still cause serious damage
TargetsExposed services, websites, devices and poorly secured systems

Why They Matter

Low technical skill does not automatically mean low risk. Automated tools can scan large numbers of systems and exploit known weaknesses quickly. An organization that leaves an outdated service exposed may therefore be attacked even without being specifically selected by an advanced adversary.

Beginner lesson: Security weaknesses do not need to be complex for an attacker to take advantage of them. Basic patching, secure configuration, and exposure management can eliminate many easy opportunities.
04 · Threat Actor #2

Cybercriminals

02 / CYBERCRIMINALS

Who Are Cybercriminals?

Cybercriminals conduct illegal cyber activity primarily for financial gain. They may operate individually, as organized groups, or through criminal ecosystems where different participants provide specialized services.

MotivationFinancial gain and profit
ActivitiesRansomware, fraud, credential theft, extortion and data theft
TargetsBusinesses, individuals, financial accounts and valuable data

Modern cybercrime can be highly organized. Cybercrime actors are generally profit-driven and may steal information, extort victims, or monetize stolen information.

Example: A criminal group gains access to a company's network, steals sensitive information, and deploys ransomware to pressure the victim into paying money.
05 · Threat Actor #3

Hacktivists

03 / HACKTIVISTS

Who Are Hacktivists?

Hacktivists are threat actors motivated primarily by political, social, or ideological causes. Their cyber activity is intended to attract attention, protest, disrupt an organization, or promote a particular viewpoint.

MotivationPolitical, social or ideological goals
ActivityDDoS, website disruption, data exposure and online campaigns
TargetsGovernments, public organizations, corporations and high-profile entities

Hacktivism remains an important part of the modern threat landscape. Hacktivist activity is a major source of reported incidents, with DDoS campaigns frequently used to create visibility and disruption.

Key idea: The attacker's goal may be publicity or disruption rather than direct financial profit.
06 · Threat Actor #4

Insider Threats

04 / INSIDER THREATS

What Is an Insider Threat?

An insider threat involves someone with legitimate or trusted access to an organization who causes, enables, or assists a security incident. The person may act deliberately or accidentally.

ActorsEmployees, contractors, administrators and trusted partners
MotivationRevenge, financial gain, coercion or no malicious intent
RiskLegitimate access can make detection and prevention more difficult

Insider threats are not limited to malicious employees. An employee who accidentally sends sensitive information to the wrong recipient or mishandles credentials can also create significant risk.

Three Useful Categories

  • Malicious insider: intentionally abuses access.
  • Negligent insider: accidentally creates a security problem.
  • Compromised insider: an attacker has obtained or controls the person's access.
07 · Threat Actor #5

Nation-State Actors

05 / NATION-STATE ACTORS

What Are Nation-State Actors?

Nation-state actors, sometimes called state-sponsored or state-nexus actors, are groups associated with or supported by a government. Their objectives can include espionage, intelligence collection, strategic influence, disruption, or military objectives.

MotivationEspionage, geopolitical or strategic objectives
CapabilityPotentially high resources, expertise and long-term access
TargetsGovernments, critical infrastructure, technology and strategic organizations

State-nexus actors are generally well-resourced and capable of long-term, targeted operations, with espionage and disruption among their key objectives.

Important distinction: "Advanced Persistent Threat" (APT) describes a type of sophisticated, persistent activity and is not simply another name for every nation-state actor. Different actors can conduct APT-style operations.
08 · Threat Actor #6

Cyberterrorism

06 / CYBERTERRORISM

What Is Cyberterrorism?

Cyberterrorism refers to the use of cyber capabilities in terrorism-related activity. The concept is generally associated with politically or ideologically motivated violence or intimidation where cyber operations play a significant role.

MotivationIdeological or extremist objectives
GoalFear, disruption, coercion or publicity
TargetsCritical services, public institutions and high-visibility systems

It is important not to label every politically motivated cyber attack as cyberterrorism. The term has a narrower meaning than general hacktivism and is best used carefully when discussing threat actor behavior.

Beginner lesson: Always separate an attacker's motivation from the technique used. Two actors might use similar technical methods while having completely different objectives.
09 · Compare the Actors

Cyber Threat Actors Compared

Actor Typical Motivation Capability Typical Targets
Script Kiddies Curiosity, attention, experimentation Low to moderate Exposed systems and vulnerable services
Cybercriminals Financial gain Low to highly organized Businesses, accounts and valuable data
Hacktivists Political or ideological causes Varies widely Governments, corporations and public organizations
Insiders Revenge, gain, coercion or accident Varies; often has legitimate access The organization they can access
Nation-State Actors Espionage, geopolitical objectives Often high Government, infrastructure and strategic targets
Cyberterrorists Ideological or extremist objectives Varies High-visibility or strategically significant targets
10 · Defensive Thinking

How Should Defenders Respond?

There is no single security control that stops every threat actor. Effective cybersecurity combines multiple layers of prevention, detection, and response.

  • Patch management: reduce known vulnerabilities.
  • Strong authentication: use MFA and protect privileged accounts.
  • Least privilege: give users only the access they need.
  • Network security: use firewalls, segmentation and monitoring.
  • Endpoint protection: monitor devices and suspicious processes.
  • Logging and SIEM: collect and correlate security events.
  • User awareness: reduce phishing and social-engineering risk.
  • Incident response: prepare for detection, containment and recovery.

These concepts connect directly with the next parts of the PasswordGeeks learning path, including Defensive Security, Networking for Cybersecurity, and Nmap.

11 · SOC Perspective

Why Threat Actors Matter to a SOC Analyst

A SOC analyst is not simply looking for "bad traffic." The analyst needs context. Knowing who might be behind an activity can help determine the likely objective, urgency, and response strategy.

For example, repeated automated scans against exposed services may look different from a targeted phishing campaign against privileged employees. Likewise, unusual activity from a legitimate internal account may require an insider-threat or account-compromise investigation.

SOC mindset: Don't only ask "What happened?" Ask "Who might do this, why would they do it, what are they trying to achieve, and what evidence supports that assessment?"
12 · Knowledge Check

Test Your Understanding

Answer all 5 questions below. If you get one wrong, don't worry — you'll get another chance to pick the correct answer. This chapter is only marked complete when all 5 answers are correct.

Solved: 0 / 5 · Not yet complete
QUESTION 01 / 05

Which type of threat actor primarily relies on existing scripts and automated tools rather than developing their own techniques?

QUESTION 02 / 05

What is the primary motivation of cybercriminals?

QUESTION 03 / 05

Which of the following is NOT necessarily considered a type of insider threat?

QUESTION 04 / 05

Which type of threat actor is most often associated with espionage, strategic objectives, and long-term targeted operations?

QUESTION 05 / 05

What is a key difference between a nation-state actor and an "APT" (Advanced Persistent Threat)?

Chapter Complete

0 / 5
Correct Answers

All 5 questions solved. This chapter is now marked complete in Module 1.

Continue Learning

Related PasswordGeeks Lessons

Types of Cybersecurity Attacks

Learn about malware, ransomware, phishing, DDoS, MITM, SQL injection and other common attacks.

Explore Attacks →

Networking for Cybersecurity

Build the networking knowledge needed to understand how attackers and defenders interact with systems.

Learn Networking →

Offensive Security

Understand how authorized security testing identifies weaknesses before real attackers can exploit them.

Explore Offensive Security →

Defensive Security

Learn how blue teams prevent, detect, and respond to cyber threats.

Explore Defensive Security →