Rethinking Cyber Adversary Categories and Motivations

July 27, 2026

Knowing which adversaries are likely to target our organizations is a critical step in managing cybersecurity risk. Those judgments shape which cybersecurity initiatives receive priority, which controls we implement, and the assumptions responders make when investigating an incident. We develop our understanding of adversaries through experience, formal education and certification, threat reports, and social media.

Traditional adversary categories provide a useful starting point, but are they sufficient for the adversaries organizations face today?

CompTIA Security+, a foundational cybersecurity certification, requires learners to compare six common threat actors: nation-states, unskilled attackers, hacktivists, insider threats, organized crime, and shadow IT. The learning objectives also separately identify attributes, such as resources, position and capability, as well as motivations, including espionage, financial gain, ideology, revenge, disruption and war (CompTIA, 2023).

Separating actors, attributes, and motivations makes sense. However, these categories classify adversaries using different characteristics: nation-state by affiliation, organized crime by economic structure, hacktivist by a cause, insider by position, and unskilled attacker by capability. Shadow IT is different still, referring to unauthorized technology use that may involve no malicious intent.

No categorization scheme can capture every adversary. The concern is not that these categories are technically wrong. It is that they may leave relevant actors and relationships underdeveloped, while encouraging assumptions about what each actor wants and can do. My goal here is not a replacement taxonomy. It is to show why the one we teach is too narrow, and to offer a starting point for expanding your own.

When Categories Become Assumptions

The same categories that shape how we identify adversaries can also shape our assumptions about their motives. Nation-states conduct war and espionage. Organized criminals pursue money. Hacktivists advance a cause. Insiders seek revenge or financial gain. Unskilled attackers look for recognition. The motivations of current cyber adversaries routinely cross traditional boundaries. Cloudflare describes North Korean operations as serving “dual requirements for strategic intelligence and illicit revenue” (Cloudflare, 2026, p. 24). The report also describes an “espionage-ransomware hybrid” that combines intellectual property theft, financial extortion, and cryptocurrency theft (Cloudflare, 2026, p. 27).

When responders treat an apparent motive as the only motive, they may scope the investigation too narrowly. A ransomware response should already include a search for persistence, compromised accounts, lateral movement, and data theft (Mandiant, 2026, p. 58). However, extortion may not explain the entire operation. If the actor also serves a state intelligence objective, information with little criminal resale value, such as defense research, infrastructure documentation, diplomatic communications or proprietary technology, may be among the operation’s primary targets. Misreading the motivation may therefore cause responders to underestimate which systems and information mattered to the adversary and how broadly the incident should be investigated.

North Korea’s remote-worker operations further blur the distinction between external adversaries and insiders. The U.S. Department of Justice reported that North Korean operatives used false or stolen identities to obtain remote employment at more than 100 U.S. companies. Some gained access to sensitive employer information, including export-controlled military technology and virtual currency. The workers generated revenue for the North Korean government and were supported by facilitators who operated laptop farms and other infrastructure (U.S. Department of Justice, 2025). Were these “employees” external state actors, fraudulent employees, financially motivated operatives, or malicious insiders? In this scenario, they are all four. Assuming the threat is only a nation-state actor may leave gaps in applicant verification, remote administration, workforce monitoring, and access controls. The traditional association between insider threats and disgruntled employees may lead investigators to treat the employee as an isolated adversary. Disabling the employee’s access may stop the immediate activity, but ending the investigation there could leave identity fraud, remote operators, shared infrastructure, other fraudulent workers, or evidence of external direction undiscovered. A broader investigation, conducted internally or with external entities, may reveal that the employee was only one part of a larger operation.

Expanding the Field of View

None of this means discarding traditional categories. They remain useful starting points, but they need to be expanded and updated to reflect new actors, relationships, capabilities, and motivations.

Nation-state activity could include direct government operations and hybrid proxies that advance state objectives while remaining separate from the state. These proxies may include contractors, criminal groups, and aligned hacktivists operating with varying levels of state direction, support, protection or tolerance (Cyfirma, 2025; FalconFeeds.io, 2025). Such arrangements extend state capabilities and provide plausible deniability. Russian-aligned cybercrime groups demonstrate that actors may support state interests without direct government control and while remaining financially motivated (CISA et al., 2022; National Security Agency, 2022).

Organized cybercrime could include traditional syndicates that adopt cyber methods and specialized actors that sell discrete services. Initial access brokers compromise networks and sell that access to other offenders, while cybercrime-as-a-service providers offer capabilities such as malware, phishing kits, stolen credentials, infrastructure, and related operational services to customers and affiliates (CISA, 2023; Europol, 2025; UNODC, 2022). CrowdStrike similarly identifies access brokers as a key part of the cybercrime ecosystem with established ties to ransomware operators and ransomware-as-a-service affiliates (CrowdStrike, 2022). These roles allow different actors to conduct separate stages of the same intrusion, and this is no longer rare: Mandiant found that 9 percent of its 2025 investigations involved two or more threat groups in the initial intrusion chain, with different groups performing different stages of the attack (Mandiant, 2026).

Our traditional view of insider threats often centers on the disgruntled employee, but insiders may also be recruited by an external adversary or unintentionally create exposure through social engineering, mistakes, and insecure workarounds. Contractors, business partners, and former employees whose access remains active can present many of the same risks. Expanding the category changes the controls we consider, from monitoring malicious activity to improving identity management, training, access removal, and the usability of security processes.

Commercial surveillance providers also complicate traditional categories. Meta documented a surveillance-for-hire industry in which commercial operators collected intelligence and compromised devices and accounts for customers. Targets included journalists, dissidents, activists, and critics of authoritarian governments (Dvilyanski et al., 2021). Atlantic Council researchers later mapped 435 entities across 42 countries within the commercial spyware market, including vendors, suppliers, investors, holding companies, and individuals (Roberts et al., 2024). The provider may be motivated by profit while the customer seeks political suppression, intelligence, commercial advantage, or personal retaliation. An expanded view needs a place for these providers, one that keeps the operator’s motive separate from the customers.

The unskilled attacker category could be refined and broadened into Unsanctioned External Individuals: any independent actor operating from outside the organization and without authorization, whatever their skill or motive. Unlike the narrower “unskilled attacker” or “script kiddie” labels, it includes novices using automated tools, unauthorized researchers, independent extortionists, vandals, exploit developers, and others acting without authorization.

Cloudflare’s GRUB1 analysis illustrates why independent actors should not be defined only by limited skill. Automated credential discovery and artificial intelligence allowed “unsophisticated, individual actors” to conduct high-impact breaches in unfamiliar software environments (Cloudflare, 2026, p. 7). An organization that treats these actors only as unskilled opportunists may prepare for automated scanning while overlooking targeted reconnaissance, extortion, data theft, or deliberate disruption. A novice searching for common vulnerabilities, a researcher operating without authorization, and an independent extortionist may all be external individuals, but their methods, objectives, and potential impact differ.

During the Incident, Set Categories Aside

A broader set of categories may help us recognize adversaries, motivations, capabilities, and relationships we might otherwise overlook. The categories here are not a finished model. Even with broader categories and a more flexible view of motivation, limits remain: adversaries adapt, relationships change, and a single intrusion may involve a network of participants with different roles, capabilities, and motivations.

Categories are most useful before an incident, when organizations plan, prioritize and teach. In the middle of a response, defenders may not yet know what kind of adversary they face. Mandiant tracks related activity as threat clusters when the evidence does not support attribution to a known group. This approach accommodates intrusions in which access providers, malware distributors, ransomware affiliates, state-directed operators, and other participants perform different roles. Defenders can respond to an intrusion involving several parties without treating them as one stable adversary with a single motive (Mandiant, 2026).

Rethinking cyber adversaries is more than a debate over terms and categories. Organizations need to reconsider which adversary categories and motivations apply to them, and to recognize that an intrusion may involve several entities whose relationships and objectives remain uncertain. This broader view can help organizations create more realistic threat scenarios, prioritize cybersecurity initiatives, select protective controls and systems, and determine how far an incident investigation must go before the organization can reasonably conclude that an incident has been contained. The categories that matter most to your organization may not be the ones named here. The more important step is to ask which adversaries and motivations our limited categories render invisible.


References

Cloudflare. (2026). Cloudflare threat report: How adversaries are weaponizing the Internet. https://www.cloudflare.com/lp/threat-report-2026/

CompTIA. (2023). CompTIA Security+ (SY0-701) certification exam objectives (Version 7). Retrieved July 20, 2026, from https://www.comptia.org/en-us/certifications/security/

CrowdStrike. (2022, February 23). Access brokers: Who are the targets, and what are they worth? https://www.crowdstrike.com/en-us/blog/access-brokers-targets-and-worth/

Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, National Security Agency, Australian Cyber Security Centre, Canadian Centre for Cyber Security, New Zealand National Cyber Security Centre, United Kingdom National Cyber Security Centre, & National Crime Agency. (2022, May 9). Russian state-sponsored and criminal cyber threats to critical infrastructure. Cybersecurity Advisory. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-110a

Cybersecurity and Infrastructure Security Agency. (2023). Acquire access (T1650). https://www.cisa.gov/eviction-strategies-tool/info-attack/T1650

Cyfirma. (2025, December 24). Plausible deniability in cyberspace: The strategic use of hacktivist proxies. Cyfirma. https://www.cyfirma.com/research/plausible-deniability-in-cyberspace-the-strategic-use-of-hacktivist-proxies/

Dvilyanski, M., Agranovich, D., & Gleicher, N. (2021). Threat report on the surveillance-for-hire industry. Meta Platforms, Inc. https://about.fb.com/wp-content/uploads/2021/12/Threat-Report-on-the-Surveillance-for-Hire-Industry.pdf

Europol. (2025). Steal, deal and repeat: How cybercriminals trade and exploit your data—Internet organised crime threat assessment 2025. Publications Office of the European Union. https://www.europol.europa.eu/cms/sites/default/files/documents/Steal-deal-repeat-IOCTA_2025.pdf

FalconFeeds.io. (2025, September 30). Proxy wars in cyberspace: Tracking nation-state influence through threat actor alliances. FalconFeeds. https://falconfeeds.io/blogs/proxy-wars-cyberspace-nation-state-threat-actor-alliances/

Mandiant (Google Cloud). (2026, March 22). M-Trends 2026: Special report. Google Cloud. https://www.gstatic.com/security-marketing/m-trends-2026-en.pdf

National Security Agency. (2022, April 20). CISA, FBI, NSA, and international partners issue advisory on demonstrated threats [Press release]. https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3004954/cisa-fbi-nsa-and-international-partners-issue-advisory-on-demonstrated-threats/

Roberts, J., Herr, T., Bansal, N., & Messieh, N. (2024, September 4). Mythical beasts and where to find them: Mapping the global spyware market and its threats to national security and human rights. Atlantic Council. https://www.atlanticcouncil.org/in-depth-research-reports/report/mythical-beasts-and-where-to-find-them-mapping-the-global-spyware-market-and-its-threats-to-national-security-and-human-rights/

United Nations Office on Drugs and Crime. (2022). Digest of cyber organized crime (2nd ed.). United Nations. https://www.unodc.org/documents/organized-crime/tools_and_publications/Digest_of_Cyber_Organized_Crime_2nd_edition_English.pdf

U.S. Department of Justice. (2025, June 30). Justice Department announces coordinated, nationwide actions to combat North Korean remote information technology workers’ illicit revenue generation schemes. https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote


by Jeremy West, senior cybersecurity program lead, Center for Infrastructure Assurance and Security at The University of Texas at San Antonio

Share the Post:

Join the NCPC mailing list