Threat actor
Also known as: attacker, adversary, hacker
The person or group behind an attack, such as a criminal gang, a foreign state, an activist or a careless insider.
Draft - this entry has not been reviewed yet.
Formal
An individual or group that causes, or could cause, harm to an organisation, described by its motive, skills and resources - for example crime for money, spying for a state, or protest.
In plain English
Knowing that bikes get stolen in your area is one thing; knowing it is the same two teenagers every Friday night tells you when and how to lock up.
In practice
CFCS rates the threat from cyber crime against Denmark as very high, so the IT lead at a Danish online shop plans mainly for criminal gangs after payment, not for spying by a foreign state.
Why it matters
Knowing who is likely to attack, and why, tells you which defences matter most for your organisation.
Technical deep dive
Threat actors are profiled along three axes - motivation, capability and resources - because these predict which targets an actor pursues and how far it will go. The conventional taxonomy distinguishes nation-state actors (often termed advanced persistent threats, APTs, motivated by espionage, pre-positioning or sabotage and backed by large budgets and patience); organised cybercriminals (financially motivated, increasingly operating a service economy); hacktivists (ideological, favouring defacement, leaks and denial of service); insiders (employees or contractors, whether malicious or negligent); and low-skill opportunists (so-called script kiddies using off-the-shelf tools). Terrorist and cyber-mercenary or commercial-spyware actors are sometimes added. The categories are not rigid: a criminal group may act as a state proxy, and a nation-state may deliberately mimic criminals to complicate attribution.
The criminal ecosystem has professionalised into specialised roles that lower the skill needed to attack. Ransomware-as-a-service (RaaS) rents tooling to affiliates for a cut; initial access brokers sell footholds into already-compromised networks; malware-as-a-service and bulletproof hosting complete the supply chain. This division of labour means the actor who breaches a network is often not the one who monetises it, which complicates both defence and attribution. Frameworks help structure the analysis: MITRE ATT&CK tracks named groups and their tactics, techniques and procedures (TTPs), and the Diamond Model of Intrusion Analysis links adversary, capability, infrastructure and victim so analysts can pivot from one observation to related activity.
Attribution - determining who is behind an intrusion - is notoriously difficult and is best treated as a probabilistic judgement across multiple lines of evidence (TTPs, infrastructure reuse, code and language artefacts, timing, and strategic intent) rather than a single smoking gun, because sophisticated actors deliberately plant false flags and reuse shared tooling. In Denmark the Danish Resilience Agency (Styrelsen for Samfundssikkerhed, SAMSIK), which absorbed the Centre for Cyber Security (CFCS) in 2025, assesses the threat from different actor categories in its national threat picture; for most Danish organisations, financially motivated cyber crime is rated the dominant everyday threat, while cyber espionage from state actors is a serious concern for government, critical infrastructure and research.
A practical misconception is preparing for the most sophisticated adversary imaginable rather than the most likely one; matching defences to a realistic threat profile (the actors that actually target your sector, of your size, in your country) allocates limited resources far better than defending against a nation-state that has no interest in you. Another is equating threat actor with an anonymous outsider and neglecting the insider, who bypasses perimeter controls by definition. The threat actor is the agent behind an adversarial threat; the threat is the potential harm, the vulnerability is the weakness the actor exploits, and the actor's motive and capability are what turn an abstract threat into a targeted, credible one.
What to learn first
Everything this builds on, foundations first.
- Threat
- →Threat actor
Relationships
- Part of
- Threat landscape
- Requires
- Threat
- Unlocks
- Insider threatMITRE ATT&CK
- Exploits
- Vulnerability
Sources & further reading
Standards & official texts
- NIST Glossary - Threat Actor · NIST
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 1 (cyberlandskabet og aktører)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…