← Back to list

KC7 Writeup — The Blame Game: Why hackers be hacking

Introduction

yxager · 2026-05-27 22:11 · 0 claps · 12.8 min read
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

KC7 Writeup — The Blame Game: Why hackers be hacking

The Blame Game: Why hackers be hacking

The Blame Game: Why hackers be hacking

Introduction

Before diving into this write-up, I highly encourage you to attempt the exercises and solve the questions on your own first. Hands-on practice is the best way to build your investigation skills!

Keep in mind that as you move through the exercise, the questions often build on one another. An answer or piece of data you uncover in one step will likely serve as the foundation for your next query.

S1: Meet The Suspects

Every cyberattack has a “who” and a “why.”

For most organizations, attribution doesn’t really matter. It’s good enough to focus on how you can defend yourself. But from an academic perspective, it’s useful to understand why hackers do what they do so that we can make sense of why we even have to defend ourselves in the first place.

When you start to understand who is behind an attack and why they chose this moment to strike, the whole incident starts to make more sense. The logs stop looking like random noise and start to read like a trail left by someone with a plan. You begin to see how their motive shapes every move they make, how it influences what you should focus on first, and how much time you really have before things start sliding out of your control.

It becomes less about chasing alerts and more about reading motive and intent. You’re stepping into the attacker’s story, trying to catch up before they make their next move.

In this module, you’ll learn to tell four types of threat actors apart, understand why the lines between them blur, and practice applying that framework to real groups you’ll actually encounter in the field.

By the end, you won’t just know the categories. You’ll know why they’re hard to apply and what to do with that uncertainty.

Before we talk about who’s attacking, let’s talk about what they want. That question, more than any technical indicator, tells you which type of attacker you’re dealing with.

There are four main categories security professionals use to classify threat actors:

  • State actors,
  • cybercriminals,
  • insider threats, and
  • hacktivists

Each has a different primary motivation, and that motivation shapes everything from their target selection to how long they’re willing to wait before striking.

Later in this module you’ll see why these categories get complicated. But you need the foundation first.

Which of the following is NOT a primary motivation category used to classify threat actors?

script kiddie

“Nation-state” actors are government-sponsored or government-directed hackers. They have resources that most criminal groups can’t match: dedicated infrastructure, full-time teams, access to zero-day vulnerabilities, and no fear of domestic prosecution. Their government protects them, funds them, and sometimes hands them their target list.

A classic example is China’s APT41, which has conducted economic espionage against pharmaceutical, technology, and defense companies. Another is Russia’s APT28, known as Fancy Bear, which targeted the 2016 US presidential election. These groups operate with patience measured in months and objectives measured in geopolitical outcomes.

Nation-state actors are also sometimes referred to as Advanced Persistent Threats.

What does the “P” in APT stand for?

Persistent

Some state actors deliberately disguise their operations to look like financially motivated crime.

They demand ransoms. They steal cryptocurrency. They mimic the tools and tactics of criminal groups so that investigators follow the wrong trail. If responders are chasing a ransomware gang, they’re not building a case against a government.

The most documented example of this is North Korea. Facing international sanctions and desperately needing foreign currency, the North Korean government turned to cybercrime as economic policy. The group carrying out these operations is known as Lazarus Group.

North Korea state actors were notoriously responsible for hacking Sony prior to the release of the movie “The interview” which would have been embarrassing for their leader

Lazarus Group has stolen from banks, crypto exchanges, and gaming platforms. They’ve deployed ransomware. By the numbers, they look like a financially motivated criminal syndicate. But the money goes to the North Korean regime, and the operations are directed by the Reconnaissance General Bureau, a military intelligence unit.

Lazarus Group is described as state-sponsored. Who sponsors them?

North Korea

Now let’s talk about cybercriminals, and clear up the biggest misconception about them: they are not lone hackers in basements.

Modern ransomware operations look more like logistics companies than underground gangs. They have developers, operators, recruiters, negotiators, and customer service representatives. They run affiliate programs with revenue splits. There are dark web job postings with competitive pay and performance reviews.

He flaunted private jets and luxury cars on Instagram. Feds used his posts to link him to alleged cyber crimes

The business model that made all of this possible is called Ransomware as a Service, or RaaS. It works exactly like it sounds. Ransomware developers build the malware, maintain the infrastructure, and lease it out to affiliates who do the actual intrusions. Affiliates keep 60 to 80 percent of whatever ransom they collect. The operator takes the rest and never has to touch a victim network.

This separation split the people who build weapons from the people who use them, and it dramatically lowered the barrier to entry for anyone who wants to run a ransomware campaign but doesn’t know how to write malware.

What does RaaS stand for?

Ransomware as a Service

A modern ransomware attack does not start with encryption. It ends there.

By the time a victim’s files are locked and a ransom note appears on screen, the attacker has typically been in the network for days or weeks. During that time they’ve mapped the environment, escalated their privileges, identified the most valuable data, and exfiltrated a copy of it. All of that happens before the encryption switch gets flipped.

This setup enabled a tactic called double extortion. Pay to get your files back. And if you don’t pay, the attacker publishes the stolen data publicly. Some groups have added a third lever: notifying your customers or regulators directly to create additional pressure.

There’s also an entire specialty profession called Initial Access Brokers, or IABs. These are hackers who break into corporate networks and then sell that access to other criminals rather than using it themselves. The intrusion and the extortion are often carried out by completely different people.

What is the tactic called where an attacker both encrypts your data AND threatens to publish it?

Double Extortion

One of the most famous ransomware attacks in US history hit Colonial Pipeline in May 2021. A DarkSide affiliate gained access to Colonial’s network, moved through it quietly, and deployed ransomware that forced the company to shut down the largest fuel pipeline in the United States.

The shutdown lasted five days. Fuel shortages spread across the southeastern US. People were filling gas cans at every station they could find. The federal government declared a state of emergency.

Photos show the impact at the pumps from the Colonial Pipeline hack

DarkSide issued a public statement saying they were apolitical and only motivated by money, and that they would be more careful about affiliate target selection in the future. They shut down shortly after, likely under significant pressure.

How many days was Colonial Pipeline shut down?

5 days

Insider threats are the silent, patient killers of entire networks, the enemy already sitting behind your firewall with a badge and a smile. Anyone with legitimate access can become the breach: employees, ex‑staff whose accounts never got nuked, contractors, vendors — all of them already past the defenses you spent years building.

Some insiders go full rogue, stealing data for cash, sabotaging systems out of spite, or selling access to nation‑states and criminal crews. Others don’t mean harm but still unleash it. One sloppy click, one exposed credential, one misconfigured system, and suddenly you’re reading headlines about another “unforeseen” catastrophe.

It’s the same playbook behind engineers walking out of Google with AI models and the fake “dream job” lure that helped North Korea crack Axie Infinity wide open.

With foreign intelligence sliding into LinkedIn DMs like it’s a recruitment marketplace — MI5 literally had to launch a national campaign to warn people — the line between outsider and insider has evaporated. The most dangerous threat in the building is the one you never see coming until the blast radius is already glowing.

How can insider threats be categorized based on intent?

negligent and malicious

Hacktivists don’t chase profit or espionage, in theory at least.

They chase impact, using disruption as a spotlight to force the world to look at whatever injustice they believe is being ignored. Their operations hit fast, loud, and publicly, turning defacements, leaks, and takedowns into digital protest art designed to dominate the narrative.

The most popular example of this is Anonymous, the faceless collective that turned a Guy Fawkes mask into a global symbol of online rebellion. Over the years, Anonymous has launched operations against governments, corporations, extremist groups, and institutions all across the ideological spectrum — always framing their actions around themes like free speech, anti‑censorship, and resistance to oppression.

When Russia invaded Ukraine in 2022, Anonymous didn’t stay quiet. Major news outlets reported that the collective declared a “cyber war” on Russia, launching waves of attacks against state media, government portals, and companies that continued operating in the country. Whether viewed as digital vigilantes or chaotic activists, hacktivists like Anonymous show how ideology, anonymity, and global connectivity can collide to create a force capable of reshaping the cyber landscape in a single night.

When Russia invaded Ukraine in 2022, Anonymous declared a cyber war on Russia and attacked Russian state media, government websites, and companies that continued operating in the country.

Anonymous is described as decentralized. What does that mean in this context?

They have no central leadership

S2: Know Your Enemy

You just learned four attacker categories. But of course, real life is a lot more messy: the categories often blur.

Some of the most dangerous threat actors in the world don’t fit cleanly into one bucket. They have multiple motivations, shift tactics depending on the target, or deliberately obscure what they’re really after.

KillNet is a good example. They emerged in early 2022 at the start of Russia’s invasion of Ukraine. They described themselves as patriotic volunteers defending Russian interests through DDoS attacks against NATO countries, their governments, hospitals, and airports. They denied any ties to the Kremlin.

Their operations aligned precisely with Russian strategic interests. They targeted exactly the countries and organizations supporting Ukraine. They maintained a military-like organizational structure with a hierarchy, subgroups, and a Telegram channel with tens of thousands of subscribers.

KillNet looks like hacktivists. But their behavior raises a question.

Based on the description above, what is the most accurate label for KillNet?

Hacktivist

On February 9, 2018, as the Winter Olympics opened in Pyeongchang, South Korea, attackers quietly tore through the Games’ IT infrastructure. WiFi cut out, the official app stopped working, the press center lost access, and TV broadcasts went dark — all in the middle of the opening ceremony. Investigators would later call the malware behind it Olympic Destroyer.

When security researchers began pulling the code apart, they found what looked like fingerprints from Lazarus Group, the well-known North Korean state hacking collective, alongside snippets that resembled the work of a Chinese threat actor. Different firms reached different conclusions, and for a while, attribution was genuinely unclear.

It was eventually traced back to Sandworm, a unit of Russian military intelligence. The North Korean and Chinese code fragments hadn’t appeared by accident — they were planted deliberately, designed to send investigators chasing the wrong countries. Russia’s motive wasn’t hard to understand: South Korea had just banned Russian athletes from competing over the state doping scandal, and the opening ceremony made for a very public target.

What is the term for planting misleading evidence in malware to make it appear to come from a different attacker?

False Flag

False flags are a strategic choice.

When a nation-state plants evidence pointing to a criminal group, investigators spend their time hunting cybercriminals. When they point to a rival nation-state, they create diplomatic friction between two countries that had nothing to do with the attack. When they demand ransoms and steal crypto, they generate revenue and cover at the same time.

From the defender’s perspective, the practical lesson is not that attribution is impossible. It is that attribution is hard, requires evidence from multiple independent sources, and should be held with appropriate confidence levels. A single technical indicator pointing at a group is not a confident attribution.

Your job in most security roles is not to name the attacker. It is to understand what they were after, stop the bleeding, and build defenses that hold regardless of who sent the attack.

True or false: a defender’s primary job during an active incident is to determine which nation-state is responsible.

False

S3: The Lineup

Now you’re going to apply the framework to five real groups.

For each one you’ll receive a short profile and choose the best-fit category. Some are clean. Some aren’t.

Starting with a clean one.

Volt Typhoon is a Chinese state-sponsored group first identified and tracked by Microsoft. Since at least 2021, they have quietly compromised U.S. critical infrastructure — including water systems, energy grids, transportation networks and communications — while conducting little to no visible post compromise activity..

The group relies exclusively on built-in Windows tools to avoid detection,a technique known as “living off the land”. In 2024, CISA and the FBI confirmed that Volt Typhoon maintained persistent access within some victim environments for up to five years before being detected. A joint advisory from U.S., U.K., and Australian intelligence agencies assessed with high confidence that the group is pre-positioning for potential sabotage in the event of a military conflict with the United States, likely related to Taiwan

FBI Director Christopher Wray described Volt Typhoon as”the defining threat of our generation” during congressional testimony in 2024.

Which attacker category best describes Volt Typhoon?

State Sponsored Actor

Salt Typhoon is a Chinese state-sponsored group attributed by CISA to China’s Ministry of State Security and named by Microsoft.

Between 2023 and 2024, Salt Typhoon compromised at least nine U.S. telecommunications providers, including AT&T, Verizon, and T-Mobile. Rather than targeting customer data such as credit card numbers or passwords,they focused on the lawful intercept systems telecom companies use to comply with court-ordered surveillance requests.

Through this access, they obtained call metadata on more than one million users-primarily in the Washington, D.C. metro area — including staff from both 2024 presidential campaigns, as well as the personal phones of Donald Trump and JD Vance. The Chair of the U.S. Senate Intelligence Committee described the incident as “the worst telecom hack in our nation’s history”.

In January 2025, the U.S. Treasury sanctioned a Chinese company linked to the operation.

Which attacker category best describes Salt Typhoon?

State Sponsored Actor

Scattered Spider (tracked by CrowdStrike; Microsoft calls them Octo Tempest) is a loosely organized group of English-speaking young people, mostly 19–25 years old, based in the US and UK. They don’t write novel malware. They call helpdesks.

They impersonate employees. They SIM-swap phones to defeat MFA. They bomb users with authentication prompts until they give in. Once inside, they deploy ransomware from RaaS partners and demand payment.

In September 2023 they hit MGM Resorts by calling the IT helpdesk, impersonating an employee, and getting credentials reset. MGM lost over $100 million. Caesars Entertainment paid them a $15 million ransom the same month. In 2025 they were linked to an attack on Marks & Spencer that took down payment systems across 1,000+ UK stores for weeks. CrowdStrike and Microsoft were both called in to respond.

Five members were indicted by the DOJ in November 2024.

Which attacker category best describes Scattered Spider?

Ransomware

This one is hard. Think carefully.

FAMOUS CHOLLIMA is a North Korean state-sponsored threat group tracked by CrowdStrike.

Their operation works differently from traditional espionage campaigns. North Korean operatives use AI-generated or stolen identities, forged documents, and deepfake video technology to secure remote IT jobs at Western technology companies. Once hired, they perform just enough legitimate work to remain employed and continue receiving salaries.

They also install remote access tools, exfiltrate sensitive data, and funnel their salaries back to Pyongyang to fund North Korea’s weapons programs. CrowdStrike responded to 304 incidents in 2024 alone — nearly one per day — a 220% year-over-year increase. Microsoft tracks related activity under the name Jasper Sleet.

In 2024, a Nashville man was indicted for running a “laptop farm”: he received laptops shipped by companies that had just hired what they thought were US-based developers, forwarded those laptops to North Korean operators, and handled the money transfers. The DOJ has indicted participants across multiple countries.

Which attacker categories best describes FAMOUS CHOLLIMA?

State Sponsored Actor and Insider Threat

Last one. This case is relatively straightforward, but it highlights an important pattern to pay attention to.

SiegedSec was a hacktivist collective active between 2022 and 2024 and documented in CrowdStrike’s threat landscape reporting. The group explicitly targeted U.S. state government websites in response to domestic policy issues, particularly anti-transgender legislation.

They leaked government documents, defaced websites, and claimed responsibility for attacks against government systems across multiple states. Their operations were consistently accompanied by public statements explaining their ideological motivations.The group made no financial demands and had no confirmed government sponsor. In 2024, the collective announced that it was disbanding.

Around the same period, GhostSec — originally formed to target ISIS infrastructure — pivoted to pro-Palestinian operations after October 2023 and claimed attacks against Israeli industrial control systems.

Both groups operated with clear ideological motivations, showed no apparent financial objective, and had no confirmed state backing.

Which attacker category best describes SiegedSec?

Hacktivist

You made it.

Here is what you know now that you didn’t before.

There are four threat actor categories: nation-state actors, cybercriminals, insider threats, and hacktivists. Each is driven by a core motivation that shapes its target selection, operational patience, and methods.

The categories blur in practice. Nation-states use criminal tools and demand ransoms. Hacktivists sometimes act as state proxies. Criminals get recruited by intelligence services. Insiders get manufactured wholesale by foreign intelligence agencies.

Attribution is hard, sometimes deliberately so. Your job during an active incident is not to name the attacker. It is to stop the attack, understand what they were after, and build better defenses.

The groups you met in this module are not theoretical. Volt Typhoon, Salt Typhoon, Scattered Spider, FAMOUS CHOLLIMA, and SiegedSec are all active or recently documented groups with real victims and real reporting from Microsoft, CrowdStrike, and Mandiant. You will encounter their successors


메타데이터
post_id
da56d82166ca
slug
kc7-writeup-the-blame-game-why-hackers-be-hacking-da56d82166ca
url
https://medium.com/@yxager/kc7-writeup-the-blame-game-why-hackers-be-hacking-da56d82166ca
canonical_url
https://medium.com/@yxager/kc7-writeup-the-blame-game-why-hackers-be-hacking-da56d82166ca
author_url
https://medium.com/@yxager
status
ok
fetched_at
2026-07-10 09:52:19