# What is a Threat Actor?

> A threat actor is an individual, group, or organization that is believed to conduct, direct, or support malicious cyber activity.

- Canonical URL: https://yellowcube.eu/glossary/threat-actor/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The label covers a wide range of motivations and capabilities, including state-sponsored operators, organized criminal groups, ransomware affiliates, hacktivists, insiders, and low-skill opportunists. A threat actor may act alone or operate inside a larger ecosystem of suppliers, access brokers, and service providers.

Attribution is a separate, evidence-dependent judgment. Public reporting assigns activity to named groups with varying confidence, naming conventions differ between research organizations, and infrastructure and tooling are frequently shared or imitated. Analysts should track observed behavior and confidence levels rather than treating a public name as established fact.

### Key points

- **Motivation categories:** Espionage, financial gain, disruption, ideology, and opportunism produce different targeting, tradecraft, and risk profiles for defenders.
- **Attribution evidence:** Infrastructure reuse, malware and tool families, operational patterns, targeting choices, language or timing cues, and corroborating intelligence all contribute — and all can be manipulated.
- **Defensive use:** Actor profiles help prioritize which tactics, techniques, and procedures to defend against, but controls should not depend on correctly guessing who is attacking.
- **Important limitation:** A threat-actor label does not prove responsibility, sponsorship, or a single controlling entity. Shared tooling, deliberate false flags, and recycled infrastructure make confident attribution difficult, and defensive conclusions drawn from the label alone can misdirect response.

### Related terms

[Advanced persistent threat (APT)](<https://yellowcube.eu/glossary/advanced-persistent-threat/>) · [Cyber espionage](<https://yellowcube.eu/glossary/cyber-espionage/>) · [Hacktivism](<https://yellowcube.eu/glossary/hacktivism/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>) · [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>)

### Sources

[ENISA, Threat Landscape](https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025) · [NIST glossary: Adversary](https://csrc.nist.gov/glossary/term/adversary) · [NIST SP 800-150, Guide to Cyber Threat Information Sharing](https://csrc.nist.gov/pubs/sp/800/150/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

