Types of Hackers & Threat Actors
Press Next → or use ← → arrow keys
What Does "Hacker" Really Mean?
The word hacker originally meant a curious, skilled problem-solver — it was a compliment at MIT in the 1960s. Movies later turned it into a synonym for "criminal". In cybersecurity, we bring the precision back: a hacker is anyone with deep system skills. What they do with those skills decides which "hat" they wear.
The Hat Spectrum — Permission Decides
The names come from old Western films: heroes wore white hats, villains wore black. The grey hat sits in between — not evil, but not authorised either.
The Three Hats in Practice
Permission: always written and scoped.
Outcome: a salary, a bounty, a safer system.
Permission: none.
Outcome: even good intentions can bring criminal charges.
Motive: money, revenge, power.
Outcome: profit — until the arrest.
White hat work is a booming profession. Companies like Google, Meta and Indian startups pay bug bounties to anyone who reports a flaw responsibly. Certifications like CEH and OSCP formalise the path.
Beyond the Three Hats
Cybercrime Is Now a Business
When the Conti gang's internal chats leaked in 2022, the world saw salary negotiations, employee-of-the-month debates and office politics — inside a ransomware gang.
Gangs now rent out their ransomware like a software subscription. Affiliates run the attacks and share the profit. The skill barrier for becoming a cybercriminal has almost disappeared.
Follow the Money — How a Gang Gets Paid
Ransoms are demanded in cryptocurrency because it crosses borders instantly. Money mules then convert and move it through many accounts to hide the trail — a process called laundering. Following this money is how police unmask gangs.
Inside the Gang — Who Does What
| Role | Job description | Legit-world equivalent |
|---|---|---|
| Malware Developers | Write and update the ransomware code | Software engineers |
| Initial Access Brokers | Break into networks, then sell that access | Lead-generation vendors |
| Affiliates | Rent the malware and run the actual attacks | Franchise owners |
| Negotiators | Chat with victims and set the ransom price | Sales / support desk |
| Money Mules | Move and launder the ransom money | Payments team |
| Bosses | Recruit, pay salaries, pick targets | Founders / management |
A division of labour means one gang can attack hundreds of victims at once. But it also creates weak links — arrest the access brokers or freeze the mules, and the whole business slows down.
Groups That Made Headlines
| Group | Type | Known for |
|---|---|---|
| Lazarus Group | State-linked | The 2016 Bangladesh Bank heist — $81 million stolen via SWIFT |
| Conti | Ransomware gang | Its 2022 chat leak exposed a full corporate structure |
| LockBit | RaaS operation | One of the most prolific ransomware services before its 2024 takedown |
| FIN7 | Financial crime | Ran a fake security company to recruit unwitting employees |
| Anonymous | Hacktivists | Politically motivated defacements and leaks, no fixed membership |
Different motives — money, politics, national interest — but the same tools: phishing, stolen credentials and unpatched systems. Defend those three doors and you defend against them all.
The Insider Threat — Danger With a Badge
An insider threat is any current or former employee, contractor or partner whose access is used to harm the organisation. The scary part: their actions look like normal logins, so firewalls and antivirus rarely notice.
Why the Firewall Can't Save You
The firewall stops the outside attacker every time. But the insider's connection never crosses the wall — it starts behind it. That is why insider incidents take so long to detect: nothing looks broken.
Six Controls That Catch Insiders
Case Study — The 2020 Twitter Takeover
There was no zero-day and no malware. Attackers — including a 17-year-old — simply phoned Twitter employees, posed as IT staff, and talked them into handing over credentials for internal admin tools. About 130 accounts were hijacked using Twitter's own systems.
A social-engineering attack turned trusted employees into compromised insiders — and the world's biggest accounts fell without a single line of exploit code.
Young attackers with modest skills, an organised plan to cash out in crypto, and insider access as the master key. Threat actor types are not separate boxes — real attacks mix them.
Know the Actor, Predict the Attack
Skills don't make someone a criminal — permission and intent do. Cybercrime is an organised industry with an org chart. And the hardest threat to stop is the one already inside the walls. Knowing who attacks tells you how they will attack.
Read the Verizon DBIR chapter on insider incidents. Explore threat actor profiles on MITRE ATT&CK. Practise the white hat path legally on TryHackMe or HackTheBox — and let the green hat in you grow into a white one.
🎭 End of tutorial · Press ← to review, or click Restart