[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Adversaries and Their Motivations (Part 2)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Rob Downs](https://unit42.paloaltonetworks.com/author/rob-downs/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 12, 2015

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Hacktivism](https://unit42.paloaltonetworks.com/category/hacktivism/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Adversaries](https://unit42.paloaltonetworks.com/tag/adversaries/)
  * [Cyber crime](https://unit42.paloaltonetworks.com/tag/cyber-crime/)
  * [Cyber espionage](https://unit42.paloaltonetworks.com/tag/cyber-espionage/)
  * [Hacktivism](https://unit42.paloaltonetworks.com/tag/hacktivism/)
  * [Motivations](https://unit42.paloaltonetworks.com/tag/motivations/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/adversaries-and-their-motivations-part-2/?pdf=download&lg=en&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/adversaries-and-their-motivations-part-2/?pdf=print&lg=en&_wpnonce=5f0cc26d8b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Adversaries%20and%20Their%20Motivations%20(Part%202)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F&title=Adversaries%20and%20Their%20Motivations%20(Part%202)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F&text=Adversaries%20and%20Their%20Motivations%20(Part%202)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Adversaries%20and%20Their%20Motivations%20(Part%202)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fadversaries-and-their-motivations-part-2%2F> "Share in Mastodon")
  [![motivations](http://blog.paloaltonetworks.com/wp-content/uploads/2015/11/motivations-500x68.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/11/motivations.png)

This post is the second in a [blog series](https://blog.paloaltonetworks.com/tag/adversaries/) describing adversaries and their motivations. In part two of the series, we'll explore the following top-level actor motivations: Cyber Espionage, Cyber Crime, and Cyber Hacktivism.

## Adversary Operational Maturity, Targeting, and Key Roles

Before we start, there are some additional concepts that add context to exploring malicious actor motivations:

* **Operational Maturity**: A gauge of the effectiveness and efficiency of a malicious actor
* **Targeting**: How an attacker goes about selecting targets
* **Key Roles**: The expertise required to conduct an attack operation, from inception to meeting objectives

### Operational Maturity

Not all malicious actors pose equal threats. Factors that influence operational maturity of an attacker include:

* **Expertise**: Ability to successfully conduct operations
* **Tradecraft**: How well an attacker evades detection and attribution throughout the lifecycle of an attack
* **Resources**: Level of commitment and persistence in launching attack campaigns

Additionally, advanced malicious actors across all motivations have successfully adopted tried-and-true techniques, generalized into repeatable and scalable operations. This facilitates broader targeting with minimized adversarial overhead.

### Targeting

Attacks executed by malicious actors can be broken out into two categories:

* **Indiscriminate**: The actor seeks to maximize gains through quantity (i.e., attacking as many entities as possible, leveraging rules of probability to fulfill objectives). Examples include general distribution spam e-mail attacks, drive-by downloads, and exploitation enabled by widely available vulnerability scanners.
* **Targeted**: The actor seeks to maximize gains through quality (i.e., selecting targets most likely to yield desired results to fulfill objectives). Examples include spear phishing, watering hole attacks/strategic web compromises (SWCs), and direct exploitation by advanced actors.

Most motivations lean further into one of these camps than the other; however, in the course of operations, any actor may leverage both methods to meet their objectives.

### Key Roles

Successful adversary operations typically rely on one or more key roles that are shared across all top-level motivations:

* **Sponsors**: Ensure adequate resources (e.g., funds, head count, training) are available to support adversarial operations.
* **Brokers**: Facilitate interaction between buyers and sellers for products (e.g., software, information) and services (e.g., development, exploitation).
* **Malware developers**: Develop, buy, and/or sell malware and their corresponding delivery mechanisms.
* **Exploit developers**: Develop, buy, and/or sell exploitation techniques against vulnerable target platforms.
* **Controllers**: Coordinate different operational campaigns to achieve adversarial objectives.
* **Attack operators**: Execute attack campaigns specified by Controllers, to include arranging for infrastructure and directly conducting attacks and exploitation.
* **Back office support**: Perform pre and post exploitation processing (e.g., research, aggregation, analysis, and staging) towards culmination of success criteria for campaign objectives.

In some scenarios, requisite roles are embodied in a single individual, but for more mature and advanced operations there are often a number of people specializing in distinct roles.

These are just things to keep in mind as we begin exploring each malicious actor motivation in greater depth.

## Cyber Espionage

Cyber Espionage includes patient, persistent, and often creative [Computer Network Exploitation (CNE)](https://www.nsa.gov/careers/career_fields/netopps.shtml) for strategic economic, political, and/or military advantage.

### Associated Actors

Actors operating under this motivation are the digital equivalents of the oft-romanticized spies sent to physically infiltrate and conduct collection operations within countries and organizations of interest. The Cyber Espionage motivation can be broken out into two categories:

* [Nation-state](https://www.merriam-webster.com/dictionary/nation-state): Nation-state cyber espionage encompasses CNE activities sponsored by the government and/or military of a country to fulfill intelligence collection requirements as prioritized by that nation-state.
* [Corporate](https://www.merriam-webster.com/dictionary/corporate): Corporate cyber espionage focuses on unfair competitive advantage within an industry.

The concept of an Advanced Persistent Threat (APT) describes an attacker aligned with the Cyber Espionage motivation, and historically was synonymous with nation-state actors. The term APT encodes who is behind an attack and why, versus the what, when, or how. Given the fuzziness of establishing high-level actor motivations due to shared Tactics, Techniques, and Procedures (TTPs) and tools, the modern APT can be defined as any actor engaged in longer term espionage-oriented CNE against one or more focal targets.

### Their Objectives

Collected information can benefit entities conducting espionage operations in various ways, including:

* **Unfair competitive insight**: Adversaries conducting CNE against nation-states and corporations can benefit from detailed views into the strengths and weaknesses of existing capabilities and offerings, as well as visibility into the strategic roadmap for future efforts. For nation-state sponsored activity, gleaned information complements other intelligence gathering methods, including traditional physical infiltration by human spies and monitoring of additional communications mediums. Unlike the legal practice of business competitive intelligence gathering, corporate espionage enables unfair competitive advantages for market positioning through illegal means.
* **Boosts to innovation**: As a secondary benefit of unfair competitive insight, theft of intellectual capital (i.e., products, services, expertise) can benefit the receiving entity by considerably reducing Research and Development (R\&D) costs and allowing for innovative leapfrogging through derivative adaptations or extensions. This information can be used to replicate strengths, exploit weaknesses, and develop counter-strategies for competitive roadmaps.
* **Leverage in negotiations**: Access to protected insider information can influence political and organizational negotiations. Examples of this include exploiting the delicate play in terms and concessions regarding military activity based on gleaned knowledge, gaming financial markets using captured non-public information, or determining the ideal bid for organizational acquisitions or work contracts through prior knowledge of competing bids or key bid evaluation factors.
* **Progressive targeting**: Operations may identify platforms, business units, and/or individuals against which subsequent, progressive attack campaigns can be launched. In some cases, progressive targeting may identify personnel for coercion, leading to insider threats within organizations.

### Additional Context for this Motivation

While there are considerable overlaps in TTPs and tools, nation-state and corporate CNE espionage-oriented operations differ in terms of targeting, scale, and extent of benefit. Nation-state sponsored CNE entails global campaigns across multiple industries, with a number of longer-term impacts, which can easily extend out for several decades and be difficult to quantify in terms of damage. Most corporate sponsored CNE includes nearer-term objectives, where damage is usually easier to quantify for a singular, competitive industry or company.

Most APTs are well resourced (i.e., funding, head count), leverage established infrastructure (whether purchased or compromised/subverted), and can be categorized as moderate to high sophistication in terms of capabilities and tradecraft. The term APT is a bit of a misnomer, as most attackers under this motivation do not employ "advanced" capabilities. Instead, they often only apply sufficient resources as required to achieve their objectives. In most attacks, a combination of social engineering and clever delivery of simple malicious payloads continues to serve adversaries well. Zero day exploits and advanced attack tools are typically held in reserve to minimize their exposure and potential detection, and only brought into play for high value strategic or tactical targets.

### Examples

Some examples of Cyber Espionage activity follow:

* [Operation Lotus Blossom: A New Nation-State Cyberthreat?](https://blog.paloaltonetworks.com/2015/06/operation-lotus-blossom/)
* [APT Group UPS Targets US Government with Hacking Team Flash Exploit](https://blog.paloaltonetworks.com/2015/07/apt-group-ups-targets-us-government-with-hacking-team-flash-exploit/)
* [Musical Chairs: Multi-Year Campaign Involving New Variant of Gh0st Malware](https://blog.paloaltonetworks.com/2015/09/musical-chairs-multi-year-campaign-involving-new-variant-of-gh0st-malware/)

## Cyber Crime

Cyber Crime is an extension of traditional criminal activity, focused on the theft of personal and account information and/or establishment of leverage over a target to achieve illicit monetary gains.

### Associated Actors

The Cyber Crime motivation includes a wide range of actor sub-types, each enabling some form of fraud and theft to be carried out. Media coverage of cybercrime activity often cultivates an image of incidents such as major data breaches being associated with traditional organized crime. While it is true that there are a number of highly organized and skilled international cybercriminal groups, the availability of open source tools and respective online tutorials has lowered the cost of entry for aspiring cybercriminals as well. Still, successfully converting stolen information into sought-after payouts and avoiding attribution (and jail time) require a number of scheme-related roles and refined tradecraft.

### Their Objectives

Actors operating under this motivation focus on direct or progressive monetary gains across various criminal scheme types:

* **Digital robbery**: Whether through a banking trojan or a data breach of financial or payment card account information, cybercrime actors seek this information to siphon and sometimes completely exhaust victim accounts. This attack scheme applies equally to businesses and individuals, with some advanced actors aiming for the larger payouts of attacking financial institutions directly.
* **Exploitation of PII**: Clearinghouses, processors, or even individuals managing personally identifiable information (PII) present ideal targets for cybercriminals. This information consists of established commodities typically used directly (i.e., identity theft) or sold in the criminal underground towards financial gain. Both alternatives can lead to progressive attacks leveraging key pieces of that information towards higher yield gains for one or more malicious actors.
* **Extortion**: This type of scheme encompasses holding data for ransom, either towards restoring it for its rightful owner (e.g., ransomware such as CryptoWall) or potentially threatening to expose sensitive information to the public or other unauthorized parties unless demands are met. This is another area where Cyber Crime mirrors Cyber Espionage benefits: depending on the sensitivity of stolen information, there also remains a probability of victim coercion towards progressive attacks in support of an adversary's ultimate objectives.

### Additional Context for this Motivation

Similar to the Cyber Espionage motivation, attacks executed by Cyber Crime actors tend towards not-so-advanced methods, relying on social engineering and simple malware. The bulk of indiscriminate cybercrime attacks relies on social engineering to either trick someone into sharing sensitive information or executing malicious code on their device. Advanced actors operating under the Cyber Crime motivation are similar to Cyber Espionage operators in terms of higher degrees of targeting, resources, and tradecraft. This is not a coincidence, as there is a significant overlap between espionage and criminal activities for a number of malicious actors, to include TTPs and tools employed.

Surprisingly, variants on financial and PII theft scams that play on the greed and/or sympathy of targets remain viable for cybercriminals to collect funds from "willing" victims. Whether it comes down to claiming a windfall inheritance from a distant relative, assisting someone with liberating major funds in a foreign bank account, or helping out a new virtual acquaintance made online with a financial bind, the probability of success for such schemes keeps them in circulation.

### Examples

Some examples of Cyber Crime activity follow:

* [419 Evolution](https://blog.paloaltonetworks.com/2014/07/unit-42-new-era-threat-intelligence/)
* [Dridex is Back and Targeting the UK](https://blog.paloaltonetworks.com/2015/10/dridex-is-back-and-targeting-the-uk/)
* [CryptoWall 3, The Cyber Threat Alliance and the Future of Information Sharing](https://blog.paloaltonetworks.com/2015/10/cryptowall-3-the-cyber-threat-alliance-and-the-future-of-information-sharing/)

## Cyber Hacktivism

Cyber Hacktivism entails activist cyber attacks that seek to influence opinion and/or reputation for specific organizations, affiliations, or causes.

### Associated Actors

The broader concept of activism encompasses both legal and illegal activities. Actors operating under the Cyber Hacktivism motivation are activists using that medium to express themselves in the latter fashion. These actors are first and foremost individuals who share a common belief or cause. In some cases, they can operate independently; in others, they may cultivate affiliations with collectives or groups.

Due to the often anti-authoritarian leanings of hacktivists, loose collectives, such as Anonymous, are the norm. Such collectives do not employ a formal leadership hierarchy; usually power within the collective gravitates towards contributors with stronger reputation and popularity. More cohesive malicious actor groups under this motivation tend to be aligned with political causes, typically advertising sympathetic or fanatic allegiance to associated governments or parties. Additionally, not all members within collectives or groups are technically proficient; some contribute in other areas such as public relations, analysis of pilfered content, or simply amplifying the impact of attacks that they support using tools provided for that purpose.

### Their Objectives

The predominant objective of malicious actors under the Cyber Hacktivism motivation is to send a message for or against a cause, which can range across political and moral polarities. The underlying goal of most associated activity is to embarrass, shame, or otherwise negatively impact confidence or trust in an organization that opposes the attacker's views. Some common attack methods used by hacktivists follow, along with context on respective objectives:

* **Denial of Service (DoS)**: DoS remains a favorite for hacktivists because it doesn't require sophisticated skills or tools. Often, it is employed in its distributed form, which maximizes the scale of mounted attacks by leveraging greater numbers of botnet or other attacking assets. The purpose of this type of attack is to disrupt operations of a target, whether strictly messaging available on websites or services exposed to users (e.g., e-mail, web portals, processing platforms). Anti-DoS service offerings have thrived due to the increasing popularity of this style of attack.
* **Release of sensitive information** : This attack method, also referred to as [doxing or doxxing](https://www.oxforddictionaries.com/definition/english/dox), involves gaining unauthorized access to a target's owned or entrusted sensitive information and releasing it to the public. This activity has a number of potential impacts, such as causing revenue loss due to disruption of e-commerce or other transactional services core to an organization's business, degrading public confidence and trust in the target, and exposing embarrassing and potentially illegal aspects of the target.
* **Website and social media defacement**: Ubiquitous web presence through websites and social media platforms makes them a hot target for adversaries. Government, military, businesses, organizations, and individuals use these platforms to advertise services, share views, and otherwise support certain initiatives or causes. Targeted disruption of these platforms is one end objective of this attack method; however, for indiscriminate attackers, compromise of any vulnerable platform to spread their message is acceptable.

### Additional Context for this Motivation

The difference between Cyber Hacktivism and other top-level malicious actor motivations is that their anticipated payout is measured in the currencies of guided public perception and satisfaction in having dealt a blow to contrary causes. In cases where purportedly hacktivist activities shift to seeking compensation of any sort, this motivation shifts from Cyber Hacktivism to another, accordingly.

The broad set of tactical options open to hacktivists makes defending against them especially challenging. They only need to affect public perception on an incident to send their message, versus confirming quantified damage (typically easier to establish for other malicious actor motivations, such as Cyber Crime and Cyber Espionage). Actors under this motivation mostly use open source or widely available tools and tend to exploit well-known (i.e., usually patched) vulnerabilities.

Given the globally distributed qualifier of a DDoS attack, the range of technical/tradecraft proficiency for attackers using respective tools and botnets can make tracing incidents back to individuals challenging. Often, attackers with weaker technical and tradecraft proficiencies are more easily attributed and face criminal charges. Attackers stronger in those areas tend to evade attribution and indictments.

### Examples

Some examples of Cyber Hacktivism activity follow:

* [Anonymous's KKK 'leak" targets the elusive online world of white nationalism](https://www.washingtonpost.com/news/the-intersect/wp/2015/11/05/anonymouss-operation-kkk-leak-targets-the-elusive-online-world-of-white-nationalism/)
* [Syrian Electronic Army Claims Responsibility For Hacking U.S. Army Website](https://www.forbes.com/sites/katevinton/2015/06/08/syrian-electronic-army-claims-responsibility-for-hacking-army-website/)
* [Cyber Berkut Graduates From DDoS Stunts to Purveyor of Cyber Attack Tools](https://www.recordedfuture.com/cyber-berkut-analysis/)

## Coming Up. . .

The next blog for this series will take a closer look at the three remaining top-level malicious actor motivations: Cyber War, Cyber Terrorism, and Cyber Mischief.

Back to top

### Tags

* [Adversaries](https://unit42.paloaltonetworks.com/tag/adversaries/ "adversaries")
* [Cyber crime](https://unit42.paloaltonetworks.com/tag/cyber-crime/ "cyber crime")
* [Cyber espionage](https://unit42.paloaltonetworks.com/tag/cyber-espionage/ "cyber espionage")
* [Hacktivism](https://unit42.paloaltonetworks.com/tag/hacktivism/ "hacktivism")
* [Motivations](https://unit42.paloaltonetworks.com/tag/motivations/ "motivations")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Palo Alto Networks Researcher Discovers Critical Vulnerabilities in Internet Explorer and Microsoft Edge](https://unit42.paloaltonetworks.com/palo-alto-networks-researcher-discovers-critical-vulnerabilities-in-internet-explorer-and-microsoft-edge/ "Palo Alto Networks Researcher Discovers Critical Vulnerabilities in Internet Explorer and Microsoft Edge")

### Table of Contents

* 

### Related Articles

* [Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "article - table of contents")
* [Insights: Increased Risk of Wiper Attacks](https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/ "article - table of contents")
* [Conducting Robust Learning for Empire Command and Control Detection](https://unit42.paloaltonetworks.com/empire-c2-helps-train-machine-learning-framework/ "article - table of contents")

## Related Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
