pk.org: Computer Security/Lecture Notes

Part 3 - Adversaries

Adversaries, their incentives, and state operations

Paul Krzyzanowski – 2026-09-08

Behind every attack is an individual, group, or state pursuing an objective. We refer to that party as an adversary. Vulnerabilities explain how an attack becomes possible. Adversaries explain why it occurs, whom it affects, and how long it persists.

The range runs from individuals acting alone to states. At the far end, cyber operations become instruments of national power, and computer security becomes part of international conflict.

Characteristics of Adversaries

Adversaries vary along five axes:

  1. Goals range from profit to political influence, espionage, sabotage, and notoriety.

  2. Risk tolerance derives from the goal. A criminal group typically seeks rapid returns at low risk. An intelligence agency will accept years of exposure to maintain a position it may never use.

  3. Resources extend from a single laptop at one end to a national research budget at the other.

  4. Expertise distinguishes an attacker who executes someone else’s tool from one who develops an original exploit.

  5. Level of access describes what the adversary already holds before an attack begins. It ranges from no access at all, through a network path from outside, to physical proximity, to the legitimate credentials of an employee or contractor. Access can be stolen, and it can be bought.

These five axes predict behavior more reliably than a threat label does. A group motivated by profit tends to withdraw once a victim ceases to be profitable. A group seeking a durable foothold, however, tends to remain.

Threat Matrix

The axes above provide a broad description of an adversary. A threat matrix uses two dimensions, expertise and focus, that are especially useful when deciding which defenses to build. Two axes are also easier to visualize.

Focus ranges from opportunistic to targeted. An opportunistic attack scans broadly and exploits whatever proves to be vulnerable. A targeted attack pursues a chosen victim.

For example, automated scanning for weak passwords occupies one end of the scale: it is opportunistic (the attacker is looking for anyone with a weak password). At the other end is an attack tailored to a specific person or organization that may be sustained over months (or years).

The two ends behave differently when a defense holds. An opportunistic attacker moves on to an easier system if an attack fails. A targeted attacker often treats the failed attempt as intelligence for the next plan. Most actual incidents fall somewhere in between.

Types of Adversaries

Hackers probe systems out of curiosity, for profit, or as part of their profession. They are frequently described using hat colors:

Criminal groups operate fraud, ransomware, and “as-a-service” offerings. Some of them act as access brokers, selling footholds, while others rent out botnets.

Malicious insiders are employees or contractors who abuse the legitimate access they already hold. Many perimeter controls assume that the attacker is external to the organization. An insider invalidates that assumption. The insider has legitimate access, the activity may appear authorized, and alerts designed for an external intrusion may never trigger.

A few other categories come up often enough to name:

Nation-states maintain offensive units within militaries and intelligence agencies. They have the funding to buy what they cannot build. They also have the patience to wait years, since their objectives are not constrained by commercial return.

Markets for Attacks

An underground economy supplies criminal operations. Botnets, stolen credentials, exploit kits, and access to compromised networks are sold as commodities.

Some vulnerabilities command published prices. Crowdfense, an exploit broker, lists $5 to $7 million for an iOS attack that requires no action from the victim. Defensive programs usually pay less. Apple’s maximum award reached $2 million in October 2025, although bonuses can raise a report above $5 million. The defensive market offers legality and repeat business, but it does not always win on price.

Ransomware has its own measurable economy. Chainalysis tracked roughly $820 million in ransom payments during 2025 and estimated that late attribution could push the eventual figure to $900 million or more. Only 28% of victims paid, while the median payment rose to $59,556.

Skill Levels

Script kiddies are low-skilled attackers who rely on tools and instructions developed by others. Phishing kits, exploit packs, and walkthrough videos have long been available, and AI assistance is now available as well. Together, these resources enable someone to launch a competent attack without even understanding it.

AI assistance has also altered what a low-skilled attacker can accomplish. According to an investigation published by Gambit Security, a small group or single operator breached nine Mexican government bodies and a financial institution between December 2025 and February 2026. The victims included the tax authority, the national electoral institute, and Mexico City’s civil registry. Gambit reported that roughly 150 GB were removed from those networks, exposing about 195 million identity and tax records.

The attackers relied on commercial AI coding assistants throughout the operation. They used them to write exploits, construct tooling, and automate exfiltration. They also used them to organize stolen data and determine what to attack next. They circumvented the products’ safeguards by framing the work as authorized testing. Those scope figures come from Gambit’s investigation. The affected agencies have not independently confirmed them.

The skill spectrum still exists, although AI assistants have lowered the barrier to coding. For example, an attacker can direct a tool to write or adapt an exploit that previously had to be discovered or written by hand. Judgment in selecting a target and patience in remaining hidden still distinguish an unskilled attacker from a skilled one.

Advanced Persistent Threats

At the high end of the skill spectrum are well-resourced adversaries that pursue significant objectives over an extended period. They adapt to defenders, and they attempt to maintain access. These adversaries are known as advanced persistent threats (APTs). Many prominent APTs are state-sponsored, although state sponsorship is common rather than part of the definition. Each word in the name carries weight:

Commonly cited examples of APTs include Russia’s Fancy Bear, China’s APT41, North Korea’s Lazarus Group, and Iran’s Charming Kitten. Different vendors frequently use different names for the same actors.

Cyber Warfare

Cyber warfare has no universally accepted boundary. Here, it refers to cyber operations carried out by or on behalf of states to disrupt, damage, or disable infrastructure or military systems.

Cyber espionage primarily involves collecting information, while cyber warfare primarily seeks to produce an effect. A state-sponsored intrusion is not automatically an act of war. Its effects, its context, and its connection to a broader conflict all inform that judgment. Unless a nation admits to an attack, it is often impossible to distinguish the actions performed by a government agency from those of private actors.

Stuxnet

Iran’s uranium enrichment facility at Natanz was air gapped. Its centrifuges were controlled by programmable logic controllers (PLCs) produced by Siemens, a German industrial manufacturer. PLCs are small industrial computers that operate motors and valves in factories and power plants.

Stuxnet was discovered in 2010. It probably reached the isolated network through removable media, although the route has not been established publicly. The malware spread across Windows systems using several previously unknown vulnerabilities and searched for a specific controller configuration. When it found that configuration, it drove the centrifuge rotors beyond their tolerances while replaying recorded normal readings to the operators.

Roughly 1,000 IR-1 centrifuges, more than ten percent of those installed, were removed and replaced in late 2009 and early 2010. The Institute for Science and International Security described this evidence as consistent with Stuxnet rather than proof of its effect, since the centrifuges also failed on their own. Stuxnet was the first widely known malware designed to damage physical equipment.

The United States

Stuxnet is generally reported to have been a joint American-Israeli program, although neither government has ever acknowledged it. That secrecy is typical. Governments rarely acknowledge offensive cyber operations, particularly when those operations occur outside an openly recognized armed conflict. Public accounts of American operations, therefore, vary in how well they are corroborated.

The clearest case on the record is Glowing Symphony, a late-2016 Cyber Command operation that gained control of servers and accounts used by the Islamic State’s media organization. Declassified after-action assessments describe it in unusual detail. Most public accounts of offensive operations instead rely on leaks or anonymous officials.

Documents released in 2014 also described the National Security Agency (NSA) intercepting American-made routers and servers while they were in transit to customers abroad. The agency installed implants, resealed the packages, and allowed delivery to continue without informing the manufacturers. Cisco’s chief executive warned President Obama that the practice would damage trust in American technology. It did. By 2014, China’s Central Government Procurement Center removed all Cisco products from its list of approved products. A sealed box from a reputable vendor was no longer evidence of a clean supply chain.

Russia and Ukraine

Russia has carried out cyber operations alongside conventional military action since at least 2015, and the effects have crossed Ukraine’s borders. Several incidents show the range:

Ukrainian-aligned groups have also attacked Russian systems. In July 2025, an attack on Aeroflot canceled more than forty flights. The attackers’ larger claims about destroyed servers and stolen data have not been independently confirmed.

China

Chinese state-sponsored operations include espionage, intellectual-property theft, and long-term positioning inside critical infrastructure. In 2023, Microsoft and U.S. agencies disclosed that Volt Typhoon had maintained access for at least five years across energy, water, communications, and transportation. The group relied on ordinary administrative tools instead of distinctive malware and collected credentials and control-system diagrams. The access itself was the objective, held in reserve.

Salt Typhoon targeted telecommunications providers, including systems used for court-authorized wiretaps. By August 2025, officials had counted more than 200 affected U.S. organizations and notified roughly 600 organizations across more than 80 countries. Entry often came through misconfigurations and known vulnerabilities in routers and virtual private network appliances, including a Cisco vulnerability patched in 2018.

A third operation shows how states can purchase capability. In August 2026, U.S. agencies identified QTFY as a contractor whose customers included China’s intelligence service and military. Its platform processed more than two million scanning and exploitation tasks in one day during 2024, while a proxy network disguised where the traffic came from. The advisory also attributed the exfiltration of data from more than 300 organizations to the company. Contractors can make state operations cheaper to repeat and harder to attribute.

Iran and Israel

Both sides carried out operations against the other’s civilian systems. One group calls itself Predatory Sparrow. It is widely assumed to be Israeli, though it has never been formally attributed. In October 2021, it shut down the payment systems at all 4,300 of Iran’s fuel stations, and in December 2023, it disabled roughly seventy percent of them again.

In June 2025, during the twelve-day war between the two countries, the group claimed to have destroyed data at Bank Sepah. It also stole about $90 million from Nobitex, Iran’s largest cryptocurrency exchange. The funds were not retained. They were transferred to addresses from which they can never be spent, which made the operation a demonstration rather than a robbery.

Iranian groups have targeted American hospitals and utilities. The FBI disclosed in 2022 that it had halted an Iranian intrusion at Boston Children’s Hospital the previous year. In November 2023, a group affiliated with Iran’s Revolutionary Guard seized control of industrial controllers at a water authority in Aliquippa, Pennsylvania.

North Korea

North Korea combines state objectives with revenue-generating cybercrime. In February 2025, attackers stole roughly $1.5 billion in cryptocurrency from the Bybit exchange. The FBI attributed the operation to North Korea. The attackers compromised a developer at Bybit’s wallet software supplier and altered what the exchange’s employees saw while they approved a routine transfer. Chainalysis placed North Korea’s cryptocurrency theft for the year at about $2 billion.

A quieter program places North Korean software developers at Western companies under fabricated identities. Accomplices maintain company laptops on American networks so the work appears domestic. An Arizona operator sentenced in July 2025 had placed workers at 309 companies and generated $17 million. The scheme is hard to detect because the developers usually complete the work.

Global Positioning System (GPS) Jamming and Spoofing

Two different attacks are often reported under the same name. Jamming overwhelms the satellite signal. Receivers can then no longer produce reliable position and time data. Avionics generally detect jamming and often alert the crew.

GPS spoofing transmits false navigation signals, and receivers accept them as genuine. This succeeds because the civilian GPS signals in widespread use are unauthenticated. Spoofing can be more difficult to detect, because the equipment may report a position confidently even when that position is incorrect. For example, aircraft in affected regions have reported locations hundreds of miles from where they actually were. Neither attack requires access to any of the target’s computers.

Reports of interference have increased rapidly. The International Air Transport Association analyzed data from 18.4 million flights and found that events involving loss of the satellite navigation signal rose about 220% from 2021 through 2024. A separate industry group measured about 300 spoofed flights per day early in 2024 and about 1,500 per day by August.

Countermeasures

Defense is not always passive. Defenders, companies, and governments sometimes act against attacker infrastructure directly, and occasionally they reach into machines they do not own. What separates these actions from an attack is authorization, scope, and testing rather than technique. They fall into four kinds:

Court-authorized botnet operations allow investigators to seize command servers, redirect the domains that malware contacts, and sometimes deliver approved cleanup to infected machines. Operations against Emotet and QakBot used these methods.

Provider-led takedowns also operate through the courts. Companies obtain injunctions that permit them to seize criminal domains. In May 2025, a federal court in Georgia granted Microsoft’s Digital Crimes Unit an order to seize roughly 2,300 domains that supported Lumma Stealer, a credential-stealing tool that Microsoft had found on more than 394,000 Windows machines in two months. The Justice Department seized the malware’s command infrastructure at the same time. Lumma activity resumed within months, which is the usual outcome.

Government malware removal goes further, since it reaches into machines the government does not own. In May 2023, the FBI acted against Snake, an espionage implant that a unit of Russia’s Federal Security Service (FSB) had used for nearly twenty years to take documents from computers in at least fifty countries. The FBI built a tool called PERSEUS that spoke Snake’s own authentication protocol, so each implant accepted it as a legitimate peer. PERSEUS then issued commands that made Snake overwrite its own components, disabling the malware without touching the host or its applications. A federal magistrate judge issued the warrant, and the owners of the affected computers were notified afterward.

Helpful worms are software that attempt similar cleanup without the official authorization, and they illustrate why the authorization is important. Welchia, also called Nachi, appeared in August 2003, six days after the Blaster worm. It spread through the same Windows flaw Blaster used, deleted Blaster from every machine it reached, downloaded Microsoft’s patch, and rebooted the host. It was even written to erase itself on January 1, 2004. But it found its targets by flooding networks with ping traffic, and that congestion did more damage than the worm it removed. It disabled most of the Navy Marine Corps Intranet, and the following month the State Department shut down its unclassified global network for nine hours, which suspended visa name checks at embassies. The payload was a patch, and the worm still took down a government network.

Hack-Backs

A hack-back refers to offensive action by a victim against an attacker. It might involve intruding into the attacker’s infrastructure to delete stolen data or to disable malware. For private entities, this is generally unlawful in the United States. It is also a bad idea for reasons unrelated to the law.

The operations above differ from a private hack-back because they operate under court authority. The U.S. Department of Justice’s position is that the Computer Fraud and Abuse Act (CFAA) generally prohibits individuals and companies from intruding into systems they do not own. That includes systems an attacker controls.

Attribution is uncertain, so the apparent source may be an innocent organization’s compromised server. A private response can damage that system, destroy evidence, interfere with an investigation, or provoke escalation.


Next: Part 4: Tracking Vulnerabilities and Risks


Lecture 1: Part 1 | Part 2 | Part 3 | Part 4
Lecture 1 Study Guide | List of terms