1
1

00:00:00,000  -->  00:00:01,620
<v Instructor>In the world of cybersecurity,</v>
2

2

00:00:01,620  -->  00:00:04,470
we refer to the attacker as a threat actor.
3

3

00:00:04,470  -->  00:00:06,060
Now, a threat actor is the term we use
4

4

00:00:06,060  -->  00:00:07,650
to describe these bad folks,
5

5

00:00:07,650  -->  00:00:09,360
those who want to do harm to your networks
6

6

00:00:09,360  -->  00:00:11,040
or steal your secure data.
7

7

00:00:11,040  -->  00:00:13,830
However, not all threat actors are created equal
8

8

00:00:13,830  -->  00:00:14,940
so there are different categories
9

9

00:00:14,940  -->  00:00:16,290
or tiers of adversaries
10

10

00:00:16,290  -->  00:00:17,670
that you're going to encounter.
11

11

00:00:17,670  -->  00:00:19,320
Some of these are considered structured,
12

12

00:00:19,320  -->  00:00:20,940
some are considered unstructured,
13

13

00:00:20,940  -->  00:00:22,410
some are more skilled than others
14

14

00:00:22,410  -->  00:00:23,520
and there are many different things
15

15

00:00:23,520  -->  00:00:26,340
that actually motivates each type of threat actor.
16

16

00:00:26,340  -->  00:00:27,240
Now in the media,
17

17

00:00:27,240  -->  00:00:28,710
you usually hear the terms hacker
18

18

00:00:28,710  -->  00:00:31,020
and cracker being used interchangeably
19

19

00:00:31,020  -->  00:00:33,390
but hacker has actually been the term most used
20

20

00:00:33,390  -->  00:00:34,410
in recent years
21

21

00:00:34,410  -->  00:00:35,880
and usually conjures up visions
22

22

00:00:35,880  -->  00:00:37,290
of somebody behind a laptop
23

23

00:00:37,290  -->  00:00:38,820
in a black hooded sweatshirt,
24

24

00:00:38,820  -->  00:00:40,590
sitting in a dark basement.
25

25

00:00:40,590  -->  00:00:41,610
Originally though,
26

26

00:00:41,610  -->  00:00:43,770
a hacker was simply a computer enthusiast
27

27

00:00:43,770  -->  00:00:45,600
and not considered a criminal.
28

28

00:00:45,600  -->  00:00:48,150
Crackers were hackers with malicious intent
29

29

00:00:48,150  -->  00:00:50,340
and those were the people who were criminals.
30

30

00:00:50,340  -->  00:00:53,430
The reason we got cracker is because it's a criminal hacker
31

31

00:00:53,430  -->  00:00:55,020
but due to the media coverage
32

32

00:00:55,020  -->  00:00:57,240
in the 1990s and early 2000s,
33

33

00:00:57,240  -->  00:00:58,800
the terms got blended together
34

34

00:00:58,800  -->  00:00:59,970
where hackers became known
35

35

00:00:59,970  -->  00:01:02,340
as these evil threat actors among us.
36

36

00:01:02,340  -->  00:01:04,380
But in the information security world,
37

37

00:01:04,380  -->  00:01:06,120
people try to retain the term hacker
38

38

00:01:06,120  -->  00:01:07,410
for computer enthusiasts
39

39

00:01:07,410  -->  00:01:09,150
and even for security professionals
40

40

00:01:09,150  -->  00:01:10,980
like cybersecurity analysts.
41

41

00:01:10,980  -->  00:01:13,140
And this led to the categorization of hackers
42

42

00:01:13,140  -->  00:01:14,970
by the different hats they wear.
43

43

00:01:14,970  -->  00:01:16,440
The term black hat hacker,
44

44

00:01:16,440  -->  00:01:18,900
also an unauthorized hacker, was developed
45

45

00:01:18,900  -->  00:01:21,630
to describe these criminal hackers or crackers.
46

46

00:01:21,630  -->  00:01:24,180
The good folks were then dubbed white hat hackers
47

47

00:01:24,180  -->  00:01:26,940
or ethical hackers or authorized hackers.
48

48

00:01:26,940  -->  00:01:28,320
But there's some hackers
49

49

00:01:28,320  -->  00:01:30,270
who sometimes operate as good folks
50

50

00:01:30,270  -->  00:01:32,040
and sometimes as bad folks
51

51

00:01:32,040  -->  00:01:34,620
and these are actually called gray hat hackers
52

52

00:01:34,620  -->  00:01:36,930
or semi authorized hackers.
53

53

00:01:36,930  -->  00:01:39,690
Now, regardless of the hat a particular hacker is wearing,
54

54

00:01:39,690  -->  00:01:41,820
they're still going to perform the same basic activities
55

55

00:01:41,820  -->  00:01:43,020
as part of their attacks
56

56

00:01:43,020  -->  00:01:44,580
if they're a black hat or a gray hat
57

57

00:01:44,580  -->  00:01:46,230
or a penetration test
58

58

00:01:46,230  -->  00:01:48,270
if they're doing it as a white hat.
59

59

00:01:48,270  -->  00:01:50,280
Generally, the hacker is first going to start out
60

60

00:01:50,280  -->  00:01:51,840
by utilizing social media
61

61

00:01:51,840  -->  00:01:53,640
to profile a vulnerable employee
62

62

00:01:53,640  -->  00:01:55,170
within an organization.
63

63

00:01:55,170  -->  00:01:56,280
Then they'll conduct
64

64

00:01:56,280  -->  00:01:58,320
some kind of social engineering campaign against them
65

65

00:01:58,320  -->  00:02:00,270
using phishing or other mechanisms,
66

66

00:02:00,270  -->  00:02:01,980
and then the threat actors can also scan
67

67

00:02:01,980  -->  00:02:04,020
and enumerate the networks to find targets
68

68

00:02:04,020  -->  00:02:06,060
and use fingerprinting and service discovery
69

69

00:02:06,060  -->  00:02:07,620
to identify vulnerable services
70

70

00:02:07,620  -->  00:02:09,510
that they can exploit and attack.
71

71

00:02:09,510  -->  00:02:10,680
If they find one,
72

72

00:02:10,680  -->  00:02:12,000
they'll then be able to exploit it
73

73

00:02:12,000  -->  00:02:13,440
to gain access to the network
74

74

00:02:13,440  -->  00:02:15,150
and even set up things like packet captures
75

75

00:02:15,150  -->  00:02:16,170
from the victim machines,
76

76

00:02:16,170  -->  00:02:17,910
key loggers or other things
77

77

00:02:17,910  -->  00:02:18,957
to learn more about the network
78

78

00:02:18,957  -->  00:02:19,950
and the computer,
79

79

00:02:19,950  -->  00:02:22,770
and then conduct lateral movement throughout the domain.
80

80

00:02:22,770  -->  00:02:25,050
Now, there are eight main types of threat actors
81

81

00:02:25,050  -->  00:02:25,883
that we're going to cover
82

82

00:02:25,883  -->  00:02:27,240
as we go through this lesson,
83

83

00:02:27,240  -->  00:02:29,610
including script kiddies, insider threats,
84

84

00:02:29,610  -->  00:02:32,640
competitors, organized crime, hacktivists,
85

85

00:02:32,640  -->  00:02:36,150
nation-state, APT, and supply chain threats.
86

86

00:02:36,150  -->  00:02:37,830
The first type of threat actor we have
87

87

00:02:37,830  -->  00:02:39,330
is known as a script kiddie.
88

88

00:02:39,330  -->  00:02:41,250
This is somebody who has the least amount of skill
89

89

00:02:41,250  -->  00:02:43,020
when it comes to being an attacker.
90

90

00:02:43,020  -->  00:02:45,120
Script kiddies tend to use other people's tools
91

91

00:02:45,120  -->  00:02:46,350
to conduct their attacks
92

92

00:02:46,350  -->  00:02:47,880
and they don't have the skills necessary
93

93

00:02:47,880  -->  00:02:49,200
to develop their own tools
94

94

00:02:49,200  -->  00:02:51,210
like more advanced attackers might.
95

95

00:02:51,210  -->  00:02:53,970
Instead, a script kiddie is going to use freely available tools
96

96

00:02:53,970  -->  00:02:54,930
found on the internet
97

97

00:02:54,930  -->  00:02:56,790
or an openly available security tool sets
98

98

00:02:56,790  -->  00:02:58,740
that pen testers might also use.
99

99

00:02:58,740  -->  00:03:00,600
This includes things like Metasploit,
100

100

00:03:00,600  -->  00:03:02,220
Aircrack-ng, John the Ripper,
101

101

00:03:02,220  -->  00:03:04,500
and many others to conduct their attacks.
102

102

00:03:04,500  -->  00:03:06,600
Using these freely available vulnerability assessment
103

103

00:03:06,600  -->  00:03:07,710
and hacking tools,
104

104

00:03:07,710  -->  00:03:10,140
these script kiddies can conduct their attacks for profit
105

105

00:03:10,140  -->  00:03:12,870
to gain credibility or just for fun.
106

106

00:03:12,870  -->  00:03:13,740
For example,
107

107

00:03:13,740  -->  00:03:16,800
there's a tool out there called Low Orbit Ion Cannon.
108

108

00:03:16,800  -->  00:03:18,060
This is a really simple program
109

109

00:03:18,060  -->  00:03:19,590
that's used by a lot of script kiddies
110

110

00:03:19,590  -->  00:03:21,660
to conduct denial of service attacks.
111

111

00:03:21,660  -->  00:03:23,040
Essentially, the script kiddie
112

112

00:03:23,040  -->  00:03:24,540
simply needs to enter a URL
113

113

00:03:24,540  -->  00:03:26,370
or IP address in the input box
114

114

00:03:26,370  -->  00:03:28,470
and then click on a button labeled go.
115

115

00:03:28,470  -->  00:03:30,690
Immediately, a barrage of traffic is going to begin
116

116

00:03:30,690  -->  00:03:32,070
to flood the victim's system
117

117

00:03:32,070  -->  00:03:34,170
to attempt a denial of service attack.
118

118

00:03:34,170  -->  00:03:35,400
It's really just that simple.
119

119

00:03:35,400  -->  00:03:36,233
There's no skill
120

120

00:03:36,233  -->  00:03:37,890
or underlying knowledge required.
121

121

00:03:37,890  -->  00:03:40,980
Instead, simply plug in a website address and hit go
122

122

00:03:40,980  -->  00:03:42,690
and now you're doing an attack.
123

123

00:03:42,690  -->  00:03:44,700
Script kiddies often also don't understand
124

124

00:03:44,700  -->  00:03:46,140
what tools they're actually using
125

125

00:03:46,140  -->  00:03:47,460
or the damage they can cause
126

126

00:03:47,460  -->  00:03:49,170
or even what actions they're really performing
127

127

00:03:49,170  -->  00:03:50,310
under the hood.
128

128

00:03:50,310  -->  00:03:52,350
That said, even these simple tools
129

129

00:03:52,350  -->  00:03:54,270
can create some really undesirable effects
130

130

00:03:54,270  -->  00:03:55,680
to your organization's network.
131

131

00:03:55,680  -->  00:03:57,420
So script kiddies are still a threat
132

132

00:03:57,420  -->  00:03:58,830
you need to think about.
133

133

00:03:58,830  -->  00:04:00,540
The second type of threat actor we have
134

134

00:04:00,540  -->  00:04:02,520
is what's known as an insider threat.
135

135

00:04:02,520  -->  00:04:04,290
Now, an insider threat is an employee
136

136

00:04:04,290  -->  00:04:05,460
or former employee
137

137

00:04:05,460  -->  00:04:07,500
who has knowledge of the organization's network,
138

138

00:04:07,500  -->  00:04:10,350
policies, procedures, and business practices.
139

139

00:04:10,350  -->  00:04:12,750
The insider threat is one of the most dangerous categories
140

140

00:04:12,750  -->  00:04:13,950
for an organization
141

141

00:04:13,950  -->  00:04:16,350
because these people actually have authorized access
142

142

00:04:16,350  -->  00:04:18,210
to the network if they're a current employee,
143

143

00:04:18,210  -->  00:04:19,590
and this makes them very dangerous
144

144

00:04:19,590  -->  00:04:22,320
and very difficult to find inside of your network.
145

145

00:04:22,320  -->  00:04:25,140
An insider threat could either be skilled or unskilled,
146

146

00:04:25,140  -->  00:04:26,760
depending on who they are.
147

147

00:04:26,760  -->  00:04:28,800
For example, an unskilled insider
148

148

00:04:28,800  -->  00:04:30,780
might try to copy the organization's files
149

149

00:04:30,780  -->  00:04:31,860
onto a thumb drive
150

150

00:04:31,860  -->  00:04:33,900
and walk out the front door with them.
151

151

00:04:33,900  -->  00:04:34,920
Even though they were authorized
152

152

00:04:34,920  -->  00:04:36,240
to access those files,
153

153

00:04:36,240  -->  00:04:37,260
they were not authorized
154

154

00:04:37,260  -->  00:04:38,400
to remove them from the network
155

155

00:04:38,400  -->  00:04:39,750
or post them online
156

156

00:04:39,750  -->  00:04:42,210
and this results in some kind of a data breach.
157

157

00:04:42,210  -->  00:04:44,460
Or you may have a very skilled insider threat
158

158

00:04:44,460  -->  00:04:46,890
who's able to elevate their own user account permissions
159

159

00:04:46,890  -->  00:04:48,000
so they can now access data
160

160

00:04:48,000  -->  00:04:49,290
from across the entire network
161

161

00:04:49,290  -->  00:04:50,700
as a system administrator
162

162

00:04:50,700  -->  00:04:51,960
and then try to grab all of that
163

163

00:04:51,960  -->  00:04:53,910
and sell it to a willing buyer.
164

164

00:04:53,910  -->  00:04:55,470
To prevent an insider threat,
165

165

00:04:55,470  -->  00:04:57,390
organizations really need to have policies
166

166

00:04:57,390  -->  00:04:59,220
and enforcement technologies in place,
167

167

00:04:59,220  -->  00:05:01,620
including things like data loss prevention systems
168

168

00:05:01,620  -->  00:05:02,760
to detect these insiders
169

169

00:05:02,760  -->  00:05:04,890
who attempt to remove data from the network.
170

170

00:05:04,890  -->  00:05:07,890
Also, all the organization's standard internal defenses
171

171

00:05:07,890  -->  00:05:09,480
need to be properly configured
172

172

00:05:09,480  -->  00:05:10,860
and cybersecurity analysts need
173

173

00:05:10,860  -->  00:05:12,330
to search through the security information
174

174

00:05:12,330  -->  00:05:13,680
and event management systems
175

175

00:05:13,680  -->  00:05:15,450
to identify any patterns of abuse
176

176

00:05:15,450  -->  00:05:17,970
in order to catch these malicious insiders.
177

177

00:05:17,970  -->  00:05:19,860
Now, when we talk about insider threats,
178

178

00:05:19,860  -->  00:05:22,560
there's also two different types of insider threats.
179

179

00:05:22,560  -->  00:05:23,760
These are known as intentional
180

180

00:05:23,760  -->  00:05:25,980
and unintentional insider threats.
181

181

00:05:25,980  -->  00:05:27,540
Now, an intentional insider threat
182

182

00:05:27,540  -->  00:05:29,610
is when an individual within an organization
183

183

00:05:29,610  -->  00:05:31,830
is deliberately seeking to cause harm,
184

184

00:05:31,830  -->  00:05:32,760
and this includes things
185

185

00:05:32,760  -->  00:05:34,440
like stealing sensitive information,
186

186

00:05:34,440  -->  00:05:35,610
disrupting operations,
187

187

00:05:35,610  -->  00:05:37,350
or even launching a cyber attack
188

188

00:05:37,350  -->  00:05:39,000
against the organization.
189

189

00:05:39,000  -->  00:05:40,590
This can include malicious insiders
190

190

00:05:40,590  -->  00:05:41,430
who've been recruited
191

191

00:05:41,430  -->  00:05:43,110
or coerced by an outside party,
192

192

00:05:43,110  -->  00:05:45,660
or those who have personal or financial motives
193

193

00:05:45,660  -->  00:05:47,760
to cause harm to the organization.
194

194

00:05:47,760  -->  00:05:48,690
On the other hand,
195

195

00:05:48,690  -->  00:05:50,490
an unintentional insider threat
196

196

00:05:50,490  -->  00:05:51,930
is going to refer to an individual
197

197

00:05:51,930  -->  00:05:52,950
within the organization
198

198

00:05:52,950  -->  00:05:54,960
who causes harm unintentionally
199

199

00:05:54,960  -->  00:05:56,160
because they're careless,
200

200

00:05:56,160  -->  00:05:57,180
they have a lack of knowledge,
201

201

00:05:57,180  -->  00:05:59,520
or it's just a simple human error.
202

202

00:05:59,520  -->  00:06:00,510
This can include actions
203

203

00:06:00,510  -->  00:06:02,250
such as falling for a phishing email,
204

204

00:06:02,250  -->  00:06:03,360
using weak passwords,
205

205

00:06:03,360  -->  00:06:05,160
or accidentally sharing sensitive information
206

206

00:06:05,160  -->  00:06:07,380
with somebody outside of the organization.
207

207

00:06:07,380  -->  00:06:08,550
Now, both intentional
208

208

00:06:08,550  -->  00:06:10,320
and unintentional insider threats
209

209

00:06:10,320  -->  00:06:11,700
can have serious consequences
210

210

00:06:11,700  -->  00:06:13,320
for an organization's security,
211

211

00:06:13,320  -->  00:06:14,153
and therefore,
212

212

00:06:14,153  -->  00:06:15,540
it's important to have measures in place
213

213

00:06:15,540  -->  00:06:18,270
to mitigate both of these types of insider threats.
214

214

00:06:18,270  -->  00:06:20,730
A solid cybersecurity strategy should include things
215

215

00:06:20,730  -->  00:06:22,770
like employee education and training,
216

216

00:06:22,770  -->  00:06:24,990
access controls, incident response planes,
217

217

00:06:24,990  -->  00:06:27,060
and regular monitoring of user activity
218

218

00:06:27,060  -->  00:06:29,160
to detect any unusual behavior.
219

219

00:06:29,160  -->  00:06:31,350
Additionally, having an incident response team
220

220

00:06:31,350  -->  00:06:33,840
and adequate incident response processes in place
221

221

00:06:33,840  -->  00:06:36,420
can help to quickly detect, contain and deal
222

222

00:06:36,420  -->  00:06:39,240
with any kind of insider threat you may encounter.
223

223

00:06:39,240  -->  00:06:42,000
The third type of threat actor is known as a competitor.
224

224

00:06:42,000  -->  00:06:43,740
Now, a competitor is a rogue business
225

225

00:06:43,740  -->  00:06:45,630
that attempts to conduct cyber espionage
226

226

00:06:45,630  -->  00:06:47,400
against your organization.
227

227

00:06:47,400  -->  00:06:49,950
Competitors are focused on stealing your proprietary data,
228

228

00:06:49,950  -->  00:06:50,970
disrupting your business,
229

229

00:06:50,970  -->  00:06:53,010
or damaging your reputation.
230

230

00:06:53,010  -->  00:06:55,230
Often, competitors will seek to use an employee
231

231

00:06:55,230  -->  00:06:57,210
as an insider threat in your organization
232

232

00:06:57,210  -->  00:06:58,740
to steal the data from you
233

233

00:06:58,740  -->  00:07:00,870
or they may attempt to break into your network
234

234

00:07:00,870  -->  00:07:02,190
over the internet.
235

235

00:07:02,190  -->  00:07:03,870
The fourth type of threat actor we have
236

236

00:07:03,870  -->  00:07:05,820
is known as organized crime.
237

237

00:07:05,820  -->  00:07:07,980
Now, organized crime is a category of threat actor
238

238

00:07:07,980  -->  00:07:10,140
that's focused on hacking and computer fraud
239

239

00:07:10,140  -->  00:07:12,570
in order to receive financial gains.
240

240

00:07:12,570  -->  00:07:14,220
Now, due to the Internet's wide reach,
241

241

00:07:14,220  -->  00:07:16,500
a criminal in one part of the world can hack the computer
242

242

00:07:16,500  -->  00:07:17,940
of somebody on the other side of the globe
243

243

00:07:17,940  -->  00:07:19,320
with relative ease
244

244

00:07:19,320  -->  00:07:21,960
and organized crime gangs often run different schemes
245

245

00:07:21,960  -->  00:07:24,090
or scams using social engineering
246

246

00:07:24,090  -->  00:07:25,650
or conducting more technical attacks
247

247

00:07:25,650  -->  00:07:26,790
using ransomware
248

248

00:07:26,790  -->  00:07:29,070
in order to steal money from their victims.
249

249

00:07:29,070  -->  00:07:31,620
Organized crime hackers tend to be well-funded
250

250

00:07:31,620  -->  00:07:34,470
and they use sophisticated attacks and tools as well.
251

251

00:07:34,470  -->  00:07:36,000
The fifth type of threat actor we have
252

252

00:07:36,000  -->  00:07:37,791
is known as a hacktivist.
253

253

00:07:37,791  -->  00:07:39,120
Now, a hacktivist tends to be comprised
254

254

00:07:39,120  -->  00:07:40,680
of politically motivated hackers
255

255

00:07:40,680  -->  00:07:41,820
who target governments,
256

256

00:07:41,820  -->  00:07:43,470
corporations and individuals
257

257

00:07:43,470  -->  00:07:45,330
to advance their own political ideologies
258

258

00:07:45,330  -->  00:07:46,500
or agendas.
259

259

00:07:46,500  -->  00:07:47,333
For instance,
260

260

00:07:47,333  -->  00:07:49,440
an environmentalist might be considered a hacktivist
261

261

00:07:49,440  -->  00:07:51,240
if they hack into a logging company
262

262

00:07:51,240  -->  00:07:52,073
because they want to see
263

263

00:07:52,073  -->  00:07:53,640
that company's stock prices fall
264

264

00:07:53,640  -->  00:07:55,110
in effort to drive them out of business
265

265

00:07:55,110  -->  00:07:57,120
and thereby, save the forest.
266

266

00:07:57,120  -->  00:07:59,160
Here, it is an environmental hacktivist
267

267

00:07:59,160  -->  00:08:00,000
who is really focused
268

268

00:08:00,000  -->  00:08:01,350
on taking this company out
269

269

00:08:01,350  -->  00:08:04,290
so the environment can have a better chance of surviving.
270

270

00:08:04,290  -->  00:08:05,790
Hacktivists can be individuals
271

271

00:08:05,790  -->  00:08:08,190
or they can be part of larger groups as well.
272

272

00:08:08,190  -->  00:08:10,410
For example, Anonymous is a really large
273

273

00:08:10,410  -->  00:08:12,240
and well-known hacktivist group.
274

274

00:08:12,240  -->  00:08:14,610
Hacktivists tend to vary in levels of organization
275

275

00:08:14,610  -->  00:08:17,040
from loosely organized to highly structured
276

276

00:08:17,040  -->  00:08:18,810
and they can have a high level of sophistication
277

277

00:08:18,810  -->  00:08:19,643
in their attacks
278

278

00:08:19,643  -->  00:08:21,120
but they tend not to be well funded
279

279

00:08:21,120  -->  00:08:22,680
because most of these folks are doing it
280

280

00:08:22,680  -->  00:08:23,850
based on their ideology
281

281

00:08:23,850  -->  00:08:24,810
and not because they're trying
282

282

00:08:24,810  -->  00:08:26,820
to seek out financial gain.
283

283

00:08:26,820  -->  00:08:28,380
Now, the next type of threat actor we have
284

284

00:08:28,380  -->  00:08:30,060
is known as a nation-state.
285

285

00:08:30,060  -->  00:08:32,220
Now, a nation-state is one of the most skilled types
286

286

00:08:32,220  -->  00:08:34,170
of threat actors you're going to encounter
287

287

00:08:34,170  -->  00:08:35,520
and this group usually has people
288

288

00:08:35,520  -->  00:08:37,050
with exceptional capability,
289

289

00:08:37,050  -->  00:08:38,640
funding and organization
290

290

00:08:38,640  -->  00:08:39,473
and they have the intent
291

291

00:08:39,473  -->  00:08:41,670
to hack a particular network or system.
292

292

00:08:41,670  -->  00:08:43,470
Nation-states don't simply pick a network
293

293

00:08:43,470  -->  00:08:44,640
at random to attack
294

294

00:08:44,640  -->  00:08:46,890
but instead, they determine specific targets
295

295

00:08:46,890  -->  00:08:48,810
to achieve their political motives.
296

296

00:08:48,810  -->  00:08:51,000
These incredibly organized teams of hackers
297

297

00:08:51,000  -->  00:08:52,410
conduct highly covert attacks
298

298

00:08:52,410  -->  00:08:54,330
over long periods in time,
299

299

00:08:54,330  -->  00:08:57,240
and so we often will refer to them as an APT
300

300

00:08:57,240  -->  00:08:59,250
or an advanced persistent threat.
301

301

00:08:59,250  -->  00:09:01,350
Now, not all APTs are nation-states
302

302

00:09:01,350  -->  00:09:04,530
but almost all nation-states are going to be considered APTs
303

303

00:09:04,530  -->  00:09:05,970
and we'll talk a little bit more about the differences
304

304

00:09:05,970  -->  00:09:07,500
between an APT and a nation-state
305

305

00:09:07,500  -->  00:09:08,730
in just a minute.
306

306

00:09:08,730  -->  00:09:11,370
Now, when we're talking about a nation-state or an APT,
307

307

00:09:11,370  -->  00:09:14,220
in general, they're going to be inside of a victimized network
308

308

00:09:14,220  -->  00:09:15,450
for six to nine months
309

309

00:09:15,450  -->  00:09:16,710
before the network defenders
310

310

00:09:16,710  -->  00:09:18,600
even discover there's an intrusion
311

311

00:09:18,600  -->  00:09:20,550
and some have actually gone several years
312

312

00:09:20,550  -->  00:09:21,540
between their breach
313

313

00:09:21,540  -->  00:09:22,650
and the eventual discovery
314

314

00:09:22,650  -->  00:09:24,450
by a networks defenders.
315

315

00:09:24,450  -->  00:09:27,600
Nation-state actors are really, really good at what they do
316

316

00:09:27,600  -->  00:09:29,070
and they're very difficult to find
317

317

00:09:29,070  -->  00:09:30,720
once they're in your network.
318

318

00:09:30,720  -->  00:09:32,400
Over the years, many nation-states
319

319

00:09:32,400  -->  00:09:34,050
have also tried to present themselves
320

320

00:09:34,050  -->  00:09:36,570
as a threat actor inside of one of the other groups
321

321

00:09:36,570  -->  00:09:39,120
like hacktivists or organized crime.
322

322

00:09:39,120  -->  00:09:41,280
This way, they can maintain a plausible deniability
323

323

00:09:41,280  -->  00:09:43,050
for the hacks they're conducting.
324

324

00:09:43,050  -->  00:09:45,510
Oftentimes, a nation-state might use the TTPs
325

325

00:09:45,510  -->  00:09:47,160
of a different nation-state as well
326

326

00:09:47,160  -->  00:09:49,530
in order to implicate them inside of an attack.
327

327

00:09:49,530  -->  00:09:50,430
And when this is done,
328

328

00:09:50,430  -->  00:09:52,740
it's known as a false flag attack.
329

329

00:09:52,740  -->  00:09:54,900
For example, back in 2015,
330

330

00:09:54,900  -->  00:09:56,220
there was a French TV network
331

331

00:09:56,220  -->  00:09:57,573
known as TV5 Monde
332

332

00:09:57,573  -->  00:09:58,950
that was taken off the air
333

333

00:09:58,950  -->  00:10:01,110
by a sophisticated cyber attack.
334

334

00:10:01,110  -->  00:10:02,760
The network's website was also defaced
335

335

00:10:02,760  -->  00:10:05,250
by a group calling itself the Cyber Caliphate
336

336

00:10:05,250  -->  00:10:06,690
and they made the attack look
337

337

00:10:06,690  -->  00:10:08,610
like it was launched by the Islamic State
338

338

00:10:08,610  -->  00:10:11,340
which is a politically motivated hacktivist group.
339

339

00:10:11,340  -->  00:10:12,630
Now, when security investigators
340

340

00:10:12,630  -->  00:10:13,800
looked into the attack though,
341

341

00:10:13,800  -->  00:10:16,290
they actually found the attack was conducted in Russian
342

342

00:10:16,290  -->  00:10:18,270
because the code used in the attack was typed
343

343

00:10:18,270  -->  00:10:19,530
with a Cyrillic keyboard
344

344

00:10:19,530  -->  00:10:20,760
during normal working hours
345

345

00:10:20,760  -->  00:10:22,890
in Moscow and St. Petersburg.
346

346

00:10:22,890  -->  00:10:24,750
If this was accurate, then it means
347

347

00:10:24,750  -->  00:10:26,190
that a Russian nation-state actor
348

348

00:10:26,190  -->  00:10:27,390
was actually trying to appear
349

349

00:10:27,390  -->  00:10:29,340
as an Islamic State hacktivist
350

350

00:10:29,340  -->  00:10:31,110
and that way, they would get the blame
351

351

00:10:31,110  -->  00:10:33,510
for the attack instead of Russia getting the blame
352

352

00:10:33,510  -->  00:10:36,120
and this makes this a false flag attack.
353

353

00:10:36,120  -->  00:10:38,040
Another issue that has been seen in recent years
354

354

00:10:38,040  -->  00:10:39,207
is supply chain attacks
355

355

00:10:39,207  -->  00:10:40,650
and these are normally conducted
356

356

00:10:40,650  -->  00:10:42,630
by nation-state actors as well.
357

357

00:10:42,630  -->  00:10:44,400
For example, in 2020,
358

358

00:10:44,400  -->  00:10:45,233
there was an attack
359

359

00:10:45,233  -->  00:10:46,740
on the company SolarWinds
360

360

00:10:46,740  -->  00:10:48,060
that was allegedly tied back
361

361

00:10:48,060  -->  00:10:50,130
to Russian nation-state actors.
362

362

00:10:50,130  -->  00:10:51,300
The threat actors hacked
363

363

00:10:51,300  -->  00:10:53,040
into the SolarWinds corporate network
364

364

00:10:53,040  -->  00:10:54,210
in order to add a backdoor
365

365

00:10:54,210  -->  00:10:56,070
into the code for SolarWinds.
366

366

00:10:56,070  -->  00:10:58,080
SolarWinds has numerous corporations
367

367

00:10:58,080  -->  00:11:00,000
and governments as their clients and users.
368

368

00:11:00,000  -->  00:11:01,440
So this backdoor
369

369

00:11:01,440  -->  00:11:03,150
that was embedded into their next update
370

370

00:11:03,150  -->  00:11:04,590
went out to all of these companies
371

371

00:11:04,590  -->  00:11:05,730
and government networks
372

372

00:11:05,730  -->  00:11:08,100
and effectively compromised all of them.
373

373

00:11:08,100  -->  00:11:10,350
Now, this meant that the nation-state actors
374

374

00:11:10,350  -->  00:11:12,480
now had control over all of those networks
375

375

00:11:12,480  -->  00:11:14,100
and be able to access them.
376

376

00:11:14,100  -->  00:11:16,260
This attack was not really directed at SolarWinds
377

377

00:11:16,260  -->  00:11:19,110
but instead, it was directed at SolarWind's customers.
378

378

00:11:19,110  -->  00:11:20,760
But to get to those customers,
379

379

00:11:20,760  -->  00:11:21,720
they had to get themselves
380

380

00:11:21,720  -->  00:11:23,040
into SolarWinds network
381

381

00:11:23,040  -->  00:11:23,873
and then put code
382

382

00:11:23,873  -->  00:11:25,890
into their distribution channels.
383

383

00:11:25,890  -->  00:11:28,500
A similar supply chain access attack was also conducted
384

384

00:11:28,500  -->  00:11:30,750
against the retailer Target in 2015
385

385

00:11:30,750  -->  00:11:32,400
by criminal attackers.
386

386

00:11:32,400  -->  00:11:34,560
Now in this case, an HVAC company
387

387

00:11:34,560  -->  00:11:36,600
that services the store's equipment was hacked,
388

388

00:11:36,600  -->  00:11:39,120
and that connection between the HVAC company system
389

389

00:11:39,120  -->  00:11:40,380
and the Target systems
390

390

00:11:40,380  -->  00:11:41,730
allowed the attacker to steal data
391

391

00:11:41,730  -->  00:11:43,470
from the retailer's point of sale systems
392

392

00:11:43,470  -->  00:11:45,090
and credit card terminals.
393

393

00:11:45,090  -->  00:11:47,250
Another attack credited to nation-states over the years
394

394

00:11:47,250  -->  00:11:48,540
that involves a supply chain
395

395

00:11:48,540  -->  00:11:49,830
was the embedding of root kits
396

396

00:11:49,830  -->  00:11:51,570
into Cisco routers and switches
397

397

00:11:51,570  -->  00:11:53,850
that were purchased from third party suppliers.
398

398

00:11:53,850  -->  00:11:54,683
And this again,
399

399

00:11:54,683  -->  00:11:56,580
is another reason why supply chain management
400

400

00:11:56,580  -->  00:11:58,770
and using trusted suppliers is so important
401

401

00:11:58,770  -->  00:12:00,330
to the security of your organization
402

402

00:12:00,330  -->  00:12:01,830
and its networks.
403

403

00:12:01,830  -->  00:12:03,330
Now in general, as I said,
404

404

00:12:03,330  -->  00:12:06,930
most nation-state actors are going to be classified as an APT
405

405

00:12:06,930  -->  00:12:10,050
but not all APTs or advanced persistent threats
406

406

00:12:10,050  -->  00:12:12,150
are going to be nation-state actors.
407

407

00:12:12,150  -->  00:12:14,700
Remember, a nation-state actor refers to a government
408

408

00:12:14,700  -->  00:12:16,260
or government affiliated group
409

409

00:12:16,260  -->  00:12:18,030
that conducts cyber attacks.
410

410

00:12:18,030  -->  00:12:20,370
These attacks can be used for a variety of reasons
411

411

00:12:20,370  -->  00:12:22,260
such as espionage, sabotage,
412

412

00:12:22,260  -->  00:12:23,820
or intelligence gathering.
413

413

00:12:23,820  -->  00:12:26,040
Nation-state actors are always going to be well-funded
414

414

00:12:26,040  -->  00:12:26,880
and well-equipped,
415

415

00:12:26,880  -->  00:12:27,713
and they have access
416

416

00:12:27,713  -->  00:12:29,460
to really sophisticated tools and techniques
417

417

00:12:29,460  -->  00:12:31,530
including zero day vulnerabilities.
418

418

00:12:31,530  -->  00:12:32,700
They're also highly motivated
419

419

00:12:32,700  -->  00:12:34,530
by political and strategic objectives
420

420

00:12:34,530  -->  00:12:37,050
and they operate on a really large scale.
421

421

00:12:37,050  -->  00:12:38,070
Now, an APT
422

422

00:12:38,070  -->  00:12:39,990
or advanced persistent threat on the other hand,
423

423

00:12:39,990  -->  00:12:42,000
is a more generic type of cyber attack
424

424

00:12:42,000  -->  00:12:44,250
where an attacker establishes a long-term presence
425

425

00:12:44,250  -->  00:12:45,120
on a network
426

426

00:12:45,120  -->  00:12:47,400
in order to gather sensitive information.
427

427

00:12:47,400  -->  00:12:48,960
These types of attacks can be carried out
428

428

00:12:48,960  -->  00:12:50,520
by a variety of different actors,
429

429

00:12:50,520  -->  00:12:51,660
including nation-states,
430

430

00:12:51,660  -->  00:12:52,890
criminal organizations,
431

431

00:12:52,890  -->  00:12:55,080
and even individual hackers.
432

432

00:12:55,080  -->  00:12:57,480
APTs are known to be well-funded, well organized
433

433

00:12:57,480  -->  00:12:58,920
and have a high level of persistence
434

434

00:12:58,920  -->  00:13:01,070
and determination in achieving their goals.
435

435

00:13:01,920  -->  00:13:03,360
APTs usually will infiltrate a network
436

436

00:13:03,360  -->  00:13:04,620
over a prolonged period
437

437

00:13:04,620  -->  00:13:06,540
from weeks to months or even years
438

438

00:13:06,540  -->  00:13:08,070
and they'll carefully hide their activity
439

439

00:13:08,070  -->  00:13:10,170
and blend in with normal network traffic
440

440

00:13:10,170  -->  00:13:11,100
and use a lot of tools
441

441

00:13:11,100  -->  00:13:12,870
that exist on the computer already
442

442

00:13:12,870  -->  00:13:15,270
which we refer to as living off the land.
443

443

00:13:15,270  -->  00:13:17,520
The main goal of an advanced persistent threat
444

444

00:13:17,520  -->  00:13:19,440
is really to harvest sensitive data,
445

445

00:13:19,440  -->  00:13:20,640
intellectual property
446

446

00:13:20,640  -->  00:13:21,960
and other sensitive information
447

447

00:13:21,960  -->  00:13:23,520
from the compromised network.
448

448

00:13:23,520  -->  00:13:25,350
So remember, the big difference here
449

449

00:13:25,350  -->  00:13:27,750
between a nation-state actor and an APT
450

450

00:13:27,750  -->  00:13:30,510
is that a nation-state actor is a group or organization
451

451

00:13:30,510  -->  00:13:32,220
that's affiliated with a government,
452

452

00:13:32,220  -->  00:13:34,410
while an APT is a type of cyber attack
453

453

00:13:34,410  -->  00:13:36,270
that's characterized by its long-term presence
454

454

00:13:36,270  -->  00:13:37,710
on a given network.
455

455

00:13:37,710  -->  00:13:38,670
So always remember
456

456

00:13:38,670  -->  00:13:41,520
that nation-state actors are almost always APTs
457

457

00:13:41,520  -->  00:13:44,253
but not all APTs are nation-state actors.
