Lección 2 de 4 · 8 min
The threat landscape: who attacks, and why
Cybercriminals, hacktivists, state-sponsored groups and insiders want different things and work in different ways. Knowing which ones realistically target you tells you where to spend your effort.
Por ahora esta página está en inglés.
“Threat landscape” is the security industry’s phrase for the whole picture of who is attacking, how, and what they are after. It changes every year, and agencies such as ENISA in Europe and CISA in the United States publish regular overviews. The details shift, but the cast of characters is remarkably stable. Four groups cover most of it, and each one has a different motive, a different level of skill and a different idea of who is worth attacking.
Cybercriminals: attacks as a business
Most attacks that ordinary people and small organisations meet are financially motivated. Cybercrime today works like an industry with specialised roles: some groups build malicious software and rent it out, some buy and sell stolen logins, some specialise in breaking into networks and selling that access to others, and some run the extortion and money laundering at the end. Phishing, infostealers that harvest saved passwords and browser cookies, business email compromise and ransomware are their bread and butter.
Criminals are mostly opportunistic. They send the same lure to millions of addresses and keep whatever bites. That is good news for defenders: basic measures such as updates, unique passwords, multi-factor authentication and caution with unexpected attachments defeat a large share of these attacks, because the attacker simply moves on to an easier victim.
Hacktivists: attacks as a statement
Hacktivists attack to make a political or social point. Their favourite tools are defacing websites, leaking documents and flooding services with traffic (distributed denial-of-service) to knock them offline for a while. Skill levels vary enormously, from volunteers running ready-made tools to capable groups. Their targets are chosen for symbolism: governments, companies in the news, organisations on the “wrong” side of a conflict. In recent years some groups presenting themselves as hacktivists have been linked to state interests, which blurs the line with the next category.
State-sponsored actors: patience and resources
Government-backed groups, often called advanced persistent threats (APTs), spy, steal intellectual property, prepare disruption of critical infrastructure and sometimes raise money for their state. CISA publishes advisories about actors linked to several countries, and MITRE ATT&CK keeps public profiles of hundreds of tracked groups and the techniques they use. What sets them apart is patience and resources: they can spend months inside a network quietly, write custom tools and use previously unknown vulnerabilities.
Most individuals are not their target. But some people are: journalists, lawyers, activists, dissidents, researchers, diplomats and employees of strategic companies. If your work touches something a government cares about, you should assume a more capable adversary, and the extra steps (hardware security keys, strict separation of devices, minimal apps, careful travel habits) are worth it.
Insider threats: the risk already inside
CISA defines an insider threat as the potential for an insider, someone with authorised access, to use that access to harm the organisation, intentionally or not. That includes the disgruntled employee who copies the customer database before leaving, but also the well-meaning colleague who emails files to a personal account, reuses a password that later leaks, or falls for a convincing phishing call. Insiders are dangerous because they already sit behind the defences built to keep outsiders out.
- Give people access to what their job needs, and remove it promptly when their role changes or they leave.
- Log access to sensitive data so unusual activity can be noticed.
- Make it easy to report mistakes without fear: most insider incidents are accidents that get worse when hidden.
Comparing the four
| Actor | Main motive | Typical methods | Who they usually target |
|---|---|---|---|
| Cybercriminals | Money | Phishing, infostealers, ransomware, fraud | Anyone who pays or falls for a lure |
| Hacktivists | Publicity, ideology | Defacement, leaks, denial of service | Symbolic organisations |
| State-sponsored | Espionage, strategic advantage, disruption | Long, quiet intrusions, custom tools, unknown flaws | Governments, strategic firms, high-value individuals |
| Insiders | Revenge, money, or simply error | Misuse of legitimate access | Their own organisation |
From landscape to your own threat model
The landscape is only useful if you apply it to yourself. Ask which of these actors would realistically want something you have, and how much effort they would spend. For most people the honest answer is opportunistic criminals, so the priority is strong basics. For people at higher risk, the course on threat modelling goes further. On a Mac, visibility helps against every category: an app that starts talking to an unfamiliar server is worth a look whoever is behind it, which is exactly what a per-app firewall like FireAI shows you.
Lo esencial
- Four actors cover most of the landscape: criminals, hacktivists, state-sponsored groups and insiders.
- Most people meet opportunistic, money-driven crime, which strong basics defeat most of the time.
- State-sponsored groups are patient and well resourced, and target specific people and organisations.
- Insider threats include honest mistakes, not only malice; limited access and easy reporting help.
Ponte a prueba
1. Which actor is most ordinary people most likely to encounter?
- State-sponsored espionage groups
- Opportunistic, financially motivated cybercriminals — Correcto.
- Hacktivists defacing their personal website
- None: individuals are never targeted
Mass phishing, infostealers and scams are aimed at anyone who falls for them; most people never attract a state actor’s attention.
2. What best describes an insider threat?
- Only a spy placed by a foreign government
- Someone with authorised access who harms the organisation, intentionally or by mistake — Correcto.
- A hacker who breaks in from outside
- Malicious software hidden inside an app
Insider threats come from people with legitimate access; many insider incidents are accidental.
3. What most distinguishes state-sponsored groups (APTs) from typical criminals?
- They only use phishing
- Patience and resources: long, quiet intrusions with custom tools and sometimes unknown vulnerabilities — Correcto.
- They never steal data
- They always announce their attacks
APTs can stay hidden for months and invest in custom capabilities, which is why higher-risk people need stronger measures.
Ponlo en práctica con FireAI
Pon esta lección en práctica en tu propia computadora.
- Rules: app, website, domain, IP or a range, forever or until you restart — Write a rule as precise as one address or as broad as an entire domain.
- Security modes: Home, Coffee shop, Paranoid, Under attack — Match FireAI’s strictness to where your Mac actually is, in one tap.
- USB Network Protection: nothing from a USB drive goes online unasked — Plug in a drive someone handed you without letting what’s on it phone home.
- Investigate a connection — Decide with the facts in front of you, not a vague warning.
Fuentes
- ENISA: Threat Landscape
- CISA: Nation-state cyber actors
- CISA: Insider threat mitigation
- MITRE ATT&CK: Groups
Ponlo en práctica en tu Mac
Prueba todas las funciones gratis durante 17 días, sin tarjeta.