Definition · External Attack Surface Management
What is Threat Actor?
Threat actor is the neutral term for whoever is on the other side. It is preferred over “hacker” in security writing because it says nothing about skill and everything about intent, and it covers groups, individuals, and automated operations run on their behalf.
Categories
- Financially motivated criminals, including ransomware operators and business email compromise crews
- State-sponsored groups, pursuing espionage, pre-positioning, or disruption
- Hacktivists, motivated by a cause and often by publicity
- Insiders, whether malicious or merely careless
- Opportunistic scanners, mass-scanning the internet for whatever answers
Vendors and researchers assign their own names to tracked groups, which is why the same operation appears under several aliases across reports.
Capability, intent, and opportunity
A useful way to think about actors is that risk needs all three. You cannot change an actor’s capability or intent; you can change opportunity. Almost everything in external attack surface work is opportunity reduction — fewer exposed services, fewer forgotten hosts, fewer unpatched edge devices.
Why the distinction is practical
Different actors behave differently at the reconnaissance stage. Mass scanners find whatever is listening within hours of it appearing, so exposure duration matters. Targeted actors invest in OSINT about your suppliers, staff, and naming conventions, so shadow IT and development hostnames matter. A programme tuned only for one of those misses the other.
Related concepts
Threat actors choose an attack vector after reconnaissance, and red team exercises exist specifically to emulate their behaviour against your own estate.