Cyber Security Basics 📂 Slides · 12 of 15 36 min read

Types of Hackers, Cybercriminal Organizations and Insider Threats

Not every hacker is a criminal. This tutorial explains white, black and grey hat hackers, plus script kiddies, hacktivists and state-sponsored groups. See how cybercriminal organizations run like real companies, how ransom money flows, and why insider threats are so hard to stop. Ends with the 2020 Twitter hack case study.

🎭

Types of Hackers & Threat Actors

Not every hacker is a criminal — and not every criminal wears a hoodie. Meet the white hats, black hats, grey hats, organised cybercrime gangs, and the most underrated danger of all: the insider.
The Three Hats More Threat Actors Cybercrime Gangs Insider Threats

Press Next → or use ← → arrow keys

Section 01

What Does "Hacker" Really Mean?

A locksmith is not a burglar
A locksmith and a burglar understand locks equally well. One protects your home. The other breaks into it.

The word hacker originally meant a curious, skilled problem-solver — it was a compliment at MIT in the 1960s. Movies later turned it into a synonym for "criminal". In cybersecurity, we bring the precision back: a hacker is anyone with deep system skills. What they do with those skills decides which "hat" they wear.
1960s"Hacker" born at MIT — as praise
3Classic hats: white, grey, black
$1M+Earned yearly by top bug bounty hunters
24/7Cybercrime gangs run like companies
Section 02

The Hat Spectrum — Permission Decides

LEGAL · PAID · PERMITTED ILLEGAL · CRIMINAL 😇 White Hat defends with permission 😐 Grey Hat no permission, mixed motives 😈 Black Hat attacks for personal gain Same skills across the whole bar — only permission and intent change
🎩
Why "Hats"?

The names come from old Western films: heroes wore white hats, villains wore black. The grey hat sits in between — not evil, but not authorised either.

Section 02 · Details

The Three Hats in Practice

😇
White Hat
the defender
Works as: penetration tester, bug bounty hunter, security analyst.
Permission: always written and scoped.
Outcome: a salary, a bounty, a safer system.
😐
Grey Hat
the uninvited tester
Does: probes systems without asking, then reports — or demands a "finder's fee".
Permission: none.
Outcome: even good intentions can bring criminal charges.
😈
Black Hat
the criminal
Does: steals data, deploys ransomware, sells access.
Motive: money, revenge, power.
Outcome: profit — until the arrest.
💼
The Career Path Is Real

White hat work is a booming profession. Companies like Google, Meta and Indian startups pay bug bounties to anyone who reports a flaw responsibly. Certifications like CEH and OSCP formalise the path.

Section 02 · Extended

Beyond the Three Hats

🧒
Script Kiddie
Low skill, borrowed tools. Downloads ready-made attack scripts without understanding them. Still dangerous — the tools work.
🌱
Green Hat
The eager beginner. Learning to hack, asking questions, practising on legal labs like TryHackMe. Tomorrow's white hat — or black hat.
📢
Hacktivist
Hacks for a cause, not cash — defacing sites and leaking data to make a political point. Example: the Anonymous collective.
🏛️
State-Sponsored
Elite teams funded by governments. Espionage, sabotage and long-term spying (APTs). The best resourced attackers on Earth.
🔴
Red Hat
The vigilante. Hunts black hats and attacks them back — noble goal, illegal methods. Not a job title you can put on LinkedIn.
🕶️
Insider
An employee, contractor or partner who misuses legitimate access. No firewall stops someone who already has the keys — more soon.
Section 03

Cybercrime Is Now a Business

Salaries, HR, performance reviews — for criminals
Forget the lone hacker in a dark room. Modern cybercriminal organisations look like tech startups: they have developers who write malware, sales teams that rent it out, customer support that helps victims pay ransoms, and HR departments that recruit talent.

When the Conti gang's internal chats leaked in 2022, the world saw salary negotiations, employee-of-the-month debates and office politics — inside a ransomware gang.
🛒
Ransomware-as-a-Service (RaaS)

Gangs now rent out their ransomware like a software subscription. Affiliates run the attacks and share the profit. The skill barrier for becoming a cybercriminal has almost disappeared.

Section 03 · Money

Follow the Money — How a Gang Gets Paid

🏥 Victim pays the ransom 🏴‍☠️ RaaS Gang splits the profit 👨‍💻 Developers build the malware 🎯 Affiliates run attacks 💰 Money Mules .
Why Crypto, Why Mules?

Ransoms are demanded in cryptocurrency because it crosses borders instantly. Money mules then convert and move it through many accounts to hide the trail — a process called laundering. Following this money is how police unmask gangs.

Section 03 · Org Chart

Inside the Gang — Who Does What

RoleJob descriptionLegit-world equivalent
Malware DevelopersWrite and update the ransomware codeSoftware engineers
Initial Access BrokersBreak into networks, then sell that accessLead-generation vendors
AffiliatesRent the malware and run the actual attacksFranchise owners
NegotiatorsChat with victims and set the ransom priceSales / support desk
Money MulesMove and launder the ransom moneyPayments team
BossesRecruit, pay salaries, pick targetsFounders / management
🧩
Why This Matters for Defenders

A division of labour means one gang can attack hundreds of victims at once. But it also creates weak links — arrest the access brokers or freeze the mules, and the whole business slows down.

Section 03 · Rogues' Gallery

Groups That Made Headlines

GroupTypeKnown for
Lazarus GroupState-linkedThe 2016 Bangladesh Bank heist — $81 million stolen via SWIFT
ContiRansomware gangIts 2022 chat leak exposed a full corporate structure
LockBitRaaS operationOne of the most prolific ransomware services before its 2024 takedown
FIN7Financial crimeRan a fake security company to recruit unwitting employees
AnonymousHacktivistsPolitically motivated defacements and leaks, no fixed membership
🔍
Spot the Pattern

Different motives — money, politics, national interest — but the same tools: phishing, stolen credentials and unpatched systems. Defend those three doors and you defend against them all.

Section 04

The Insider Threat — Danger With a Badge

Walls don't stop people who live inside them
A castle can have the tallest walls and the deepest moat. None of it matters if the gatekeeper opens the door — or simply forgets to lock it.

An insider threat is any current or former employee, contractor or partner whose access is used to harm the organisation. The scary part: their actions look like normal logins, so firewalls and antivirus rarely notice.
😠
Malicious Insider
wants to harm
Steals data or sabotages systems — for money, revenge, or a new employer.
🤦
Negligent Insider
means no harm
Clicks phishing links, loses laptops, shares passwords. The most common type by far.
🎣
Compromised Insider
hijacked account
An outsider steals an employee's credentials and acts as them from the inside.
Section 04 · Why It Works

Why the Firewall Can't Save You

INSIDE THE COMPANY NETWORK 😈 Outside Attacker blocked at the wall Firewall 🧑‍💼 Insider already has the keys 💾 Sensitive Data 💥
🔑
The Wall Only Faces Outward

The firewall stops the outside attacker every time. But the insider's connection never crosses the wall — it starts behind it. That is why insider incidents take so long to detect: nothing looks broken.

Section 04 · Defence

Six Controls That Catch Insiders

🛡️ INSIDER DEFENCE PLAYBOOK
1
Least privilege. Give every account only the access its job needs. An intern should not be able to open payroll.
2
Separation of duties. No single person should be able to both approve and execute a critical action alone.
3
Monitor behaviour, not just borders. Alert on the unusual: a 3 a.m. download of 10,000 files is a signal, even from a valid account.
4
Fast offboarding. The day someone resigns, their access review starts. Old accounts of ex-employees are open doors.
5
Train the negligent away. Most insider damage is accidental. Phishing drills and awareness sessions shrink it directly.
6
Build a speak-up culture. Colleagues usually notice trouble first. Make reporting concerns easy and safe.
Section 05

Case Study — The 2020 Twitter Takeover

Obama, Musk and Apple all "tweeting" a Bitcoin scam
One afternoon, the accounts of Barack Obama, Elon Musk, Bill Gates and Apple all posted the same message: "Send Bitcoin, get double back."

There was no zero-day and no malware. Attackers — including a 17-year-old — simply phoned Twitter employees, posed as IT staff, and talked them into handing over credentials for internal admin tools. About 130 accounts were hijacked using Twitter's own systems.

A social-engineering attack turned trusted employees into compromised insiders — and the world's biggest accounts fell without a single line of exploit code.
🎭
Every Theme in One Attack

Young attackers with modest skills, an organised plan to cash out in crypto, and insider access as the master key. Threat actor types are not separate boxes — real attacks mix them.

FINAL

Know the Actor, Predict the Attack

3Classic hats: white, grey, black
6More actor types beyond the hats
6Roles inside a modern cybercrime gang
3Kinds of insider: malicious, negligent, compromised
6Controls that catch insiders
130Accounts hijacked in the Twitter hack
🎯
What You Now Know

Skills don't make someone a criminal — permission and intent do. Cybercrime is an organised industry with an org chart. And the hardest threat to stop is the one already inside the walls. Knowing who attacks tells you how they will attack.

📚
Where To Go Next

Read the Verizon DBIR chapter on insider incidents. Explore threat actor profiles on MITRE ATT&CK. Practise the white hat path legally on TryHackMe or HackTheBox — and let the green hat in you grow into a white one.

🎭 End of tutorial · Press to review, or click Restart