Definition · External Attack Surface Management

What is Threat Actor?

Threat actor is the neutral term for whoever is on the other side. It is preferred over “hacker” in security writing because it says nothing about skill and everything about intent, and it covers groups, individuals, and automated operations run on their behalf.

Categories

  • Financially motivated criminals, including ransomware operators and business email compromise crews
  • State-sponsored groups, pursuing espionage, pre-positioning, or disruption
  • Hacktivists, motivated by a cause and often by publicity
  • Insiders, whether malicious or merely careless
  • Opportunistic scanners, mass-scanning the internet for whatever answers

Vendors and researchers assign their own names to tracked groups, which is why the same operation appears under several aliases across reports.

Capability, intent, and opportunity

A useful way to think about actors is that risk needs all three. You cannot change an actor’s capability or intent; you can change opportunity. Almost everything in external attack surface work is opportunity reduction — fewer exposed services, fewer forgotten hosts, fewer unpatched edge devices.

Why the distinction is practical

Different actors behave differently at the reconnaissance stage. Mass scanners find whatever is listening within hours of it appearing, so exposure duration matters. Targeted actors invest in OSINT about your suppliers, staff, and naming conventions, so shadow IT and development hostnames matter. A programme tuned only for one of those misses the other.

Threat actors choose an attack vector after reconnaissance, and red team exercises exist specifically to emulate their behaviour against your own estate.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.