Cyber Threat Hierarchy: Scammers, States & Ethical Hunters

Cybercriminals and scammers form one category of malicious actors focused on personal or group financial gain through deception or opportunistic access. Nation-backed actors form a separate category driven by state objectives, with far greater resources, persistence, and strategic intent. Treating them as an umbrella under a single prestigious label risks elevating low- and mid-tier criminals and creates a false sense that systems tolerate them. Clear separation by capability, tactics, and cumulative dollar amounts stolen provides accurate hierarchy and supports accountability.

Common capability levels for cybercriminals and scammers

These levels reflect observed patterns from public on-chain mapping, investigations, and protective intelligence work. They emphasize real operational differences rather than labels alone.

Low-level Actors rely almost exclusively on social engineering. They use ready-made phishing panels, spoofed emails, and phone calls while posing as legitimate support from exchanges or hardware wallet providers. Technical skill is minimal; success depends on convincing victims to approve transactions, share seed phrases, or reset 2FA themselves. Operational security is weak: they record and share taunting calls, flex stolen balances in Telegram or Discord groups, gamble proceeds on casinos, and leave extensive chat logs, screenshots, and on-chain trails. Cumulative totals typically stay under roughly $10 million across multiple smaller incidents. Division of labor may exist with separate infrastructure providers, but the core activity remains high-volume, low-sophistication deception.

Example drawn from mapped investigations: Man hands aka Tiffany M. operated as a caller in hardware wallet and centralized exchange support impersonation scams tied to at least $5 million. Tactics included spoofed BitcoinIRA emails under false names, phone calls guiding victims into draining Trezor wallets or Coinbase accounts, immediate flexing of proceeds in private groups, taunting victims while still on the line, and gambling stolen funds. Associates supplied phishing panels. Poor OPSEC and public flexing enabled detailed public mapping and documentation.

Additional low-level patterns from recent protective mapping include high-volume fraud infrastructure that routes victims through advertising to fake brand sites for payment and personal-data collection, with social platforms and messaging apps serving as the distribution layer.

Mid-level Actors show improved coordination, better laundering paths through instant exchanges and mixers, and sometimes limited insider or privileged access. Social engineering becomes multi-step or targets higher-value accounts. They may maintain longer operational windows, move funds more carefully after theft, and operate in small crews with clearer roles. Flexing still occurs but is riskier and often leads to exposure. Cumulative totals commonly range from $10 million into the low hundreds of millions across linked incidents. These actors still lack custom malware development or long-term network persistence.

Examples from mapped cases: Dritan Kapllani Jr. has been tied to approximately $19 million in social engineering thefts against crypto holders. Activity included flexing luxury purchases and live wallet balances during band-for-band calls that revealed addresses linked to stolen funds. John Daghita, known as Lick, was linked to more than $46 million stolen from U.S. Marshals Service seized crypto wallets, with broader suspected activity exceeding $90 million including other victims. Access came through his father’s company holding a government contract for managing forfeited digital assets. Exposure occurred during a recorded band-for-band argument showing large transfers; he was later arrested. Tactics combined insider-enabled access with subsequent laundering and public taunting.

Further mid-level patterns observed in threat-hunting pipelines include packaged malware-delivery services such as evolving ClickFix variants that combine steganography, browser cache abuse, fileless execution, and blockchain-based command-and-control, as well as loaders like HollowFrame that deploy via phishing documents, PowerShell, DLL side-loading, scheduled-task persistence, and defenses weakening.

Higher criminal These involve coordinated multi-person crews executing sophisticated, multi-stage social engineering against single high-value targets. Attackers chain impersonations across different services, reset security controls in sequence, and rapidly disperse funds across many exchanges and chains. OPSEC improves relative to lower levels yet still fails under intensive on-chain and open-source scrutiny. Totals for individual campaigns can reach hundreds of millions.

Example from mapped investigations: The crew associated with Greavys, Wiz, and Box executed a highly sophisticated social engineering attack that stole approximately $243 million from a single Genesis creditor. Tactics included sequential calls spoofing Google Support to compromise accounts, followed by Gemini support impersonation to reset 2FA and authorize transfers of over 4,000 BTC. Funds were quickly split and laundered across multiple assets and exchanges. Public mapping contributed to arrests and fund freezes.

Nation-backed actors as a distinct category

These operate with state sponsorship or direction. Goals extend beyond personal enrichment to regime funding, sanctions evasion, or strategic disruption. They possess sustained resources for custom tooling, supply-chain compromises, zero-day research, long dwell times, and professional money-laundering infrastructure. Attribution often requires extensive forensic graphs, timing analysis, and test-transaction patterns. Cumulative impact routinely reaches hundreds of millions to billions across campaigns.

Example: North Korea-linked Lazarus Group activity includes the February 2025 Bybit incident in which approximately $1.5 billion in Ethereum-related assets was drained through a sophisticated supply-chain compromise of wallet interface infrastructure. Prior campaigns across dozens of incidents have totaled billions overall. Independent on-chain analysis rapidly attributed the Bybit theft, enabling industry freezes, law-enforcement confirmation, and recovery efforts.

Additional nation-backed pattern from recent mapping: Russian threat group UAC-0145, linked to Sandworm/APT44, targets Ukrainian IT professionals through fake job interviews. Attackers pose as recruiters, shift conversations to Telegram and Zoom, and deliver supposed technical-assessment VPN configurations as the delivery mechanism. Parallel reporting covers Russian-linked cyber-espionage campaigns such as Laundry Bear relying on compromised credentials against government, defense, and critical infrastructure targets.

Classic hackers: exposing truth through controlled intrusion

Separate from the criminal and nation-backed categories sits the classic hacker in the original sense: individuals or small teams who perform intrusions or deep reconnaissance solely to expose residual risks, surface hidden truths about system weaknesses, and improve defenses. The only action that crosses a boundary is the authorized or self-directed intrusion itself; there is no theft, no taunting of victims, no financial gain, no data exfiltration for sale, and no persistence for later abuse. The work is clean, precise, and oriented toward documentation and remediation. When executed against one’s own assets or with clear protective intent, it is perfect in purpose.

This approach inverts the adversary’s methods without adopting the adversary’s goals. Practitioners treat legitimate systems as targets, run the same external techniques an opportunistic or sophisticated actor would use, and publish the findings so that residual surfaces become visible and fixable.

Concrete examples drawn directly from work published on @unccno and Quantitative Security illustrate the model:

  • A deliberate, time-boxed internal security audit of quantitativesecurity.org treated the live Squarespace-hosted site as an external target. Techniques included DNS and registration mapping, Certificate Transparency review, service fingerprinting, large-scale host and path probing of co-tenant neighbors, and correlation against live defensive sensors QuantC and QuantumGuard. The origin was never compromised. The exercise exposed the residual attack surface that persists on legitimate multi-tenant SaaS platforms: missing SPF and DMARC enabling trivial email spoofing, dual Go net/http and Squarespace Server fingerprints that can confuse tools, domain lifecycle windows, clone feedstock, and shared-IP reputation noise from nearly two thousand .academy neighbors resolving to the same anycast edges. The output was a full protective-intelligence case study that prioritizes identity controls and operational clarity rather than any claim of origin takeover.

  • Mapping of NTP Pool volunteer servers revealed outdated OpenSSH from 2014, obsolete databases, and residential Guacamole gateways answering public time queries. No active threat-actor attribution was claimed on those specific hosts; the configurations themselves were documented as the exact class that can be turned into covert C2, amplification nodes, or time-manipulation points. The result is a protective brief for anyone relying on public time sources.

  • Enrichment and prioritization pipelines at Quantitative Security take noisy telemetry—router logs, IP data, raw network observations—and reduce it to clear, attributed, ranked targets. Public information is used only for cross-referencing already discovered targets. Practical breakdowns of these workflows are shared so independent researchers and bug hunters can raise signal quality.

  • Threat-hunting posts emphasize separating signal from noise, exposing decoys, copycats, and false flags that sophisticated adversaries deploy to distract defenders, and identifying activity designed to blend in. The focus remains on uncovering what is actually present rather than chasing the obvious.

These classic-hacker actions stay within the boundary of exposure and improvement. They produce actionable residual-risk maps, sensor-tuning ground truth, and public documentation that strengthens the overall environment. In hierarchy terms they sit outside criminal and nation-backed categories entirely: capability is high, dollar impact is zero, and the sole “intrusion” serves truth and defense.

Tactics section by tier

Tactics scale with capability and dollar impact. The patterns below draw from the mapped crypto cases and concurrent protective-intelligence observations, including self-recon of residual SaaS surfaces, enrichment pipelines that reduce noisy telemetry to ranked targets, and open reporting of active campaigns.

Low-level tactics center on pure social engineering and volume. Support impersonation via phone and spoofed email, basic phishing panels, high-volume fake brand or shop sites fed by social and messaging distribution, and simple post-compromise flexing or taunting. Residual identity gaps such as missing SPF/DMARC on legitimate domains enable spoofed-mail narratives without any origin compromise. Browser-session takeover via cookie dumping and process injection appears as a cheap post-exploitation step once initial access is gained.

Mid-level tactics add packaging and limited technical chaining. Multi-step social engineering, insider or contract-derived access abuse, steganography and fileless loaders such as ClickFix or HollowFrame variants that abuse browser cache, PowerShell, DLL side-loading, and blockchain C2, plus rapid laundering through instant exchanges. Deepfakes begin appearing against identity-verification layers. Sensor noise from multi-tenant platforms and dual service fingerprints can be leveraged for camouflage or detection confusion.

Higher criminal and nation-backed tactics emphasize persistence, custom delivery, and strategic scale. Layered support impersonation across providers, supply-chain or interface compromises, zero-click or RCE paths such as those observed in meeting software or unpatched services like GeoServer SQL injection leading to remote code execution, long-term reconnaissance of shared infrastructure, and professional laundering. Nation-backed operations further incorporate fake-recruitment funnels, VPN or assessment lures, and infrastructure that can be repurposed for C2, amplification, or time-manipulation points. Self-recon exercises that deliberately map DNS, Certificate Transparency, reverse-IP neighbors, and live sensor streams under load reveal how legitimate multi-tenancy and residual brand surfaces create the same external view an adversary would exploit.

Classic-hacker tactics mirror the above reconnaissance methods but invert the intent. Ownership and consistency checks via dig, WHOIS/RDAP, and Certificate Transparency; service and implementation fingerprinting; host and path surface mapping at scale; correlation against live defensive sensors; explicit testing for phishing-kit indicators that return negative results; and full documentation of residual identity, multi-tenancy, and clone risks. The same class of techniques used against organizations every day is run against one’s own assets so that internal audits earn their keep and the truth of residual risk becomes visible.

Threat hunters and the broader response environment

Threat hunters proactively map wallets, correlate recordings and chat logs, reconstruct attack timelines, and publish evidence that feeds law enforcement and private freezes. Parallel protective work designs enrichment and prioritization pipelines that turn raw router logs, IP data, and network observations into attributed, ranked targets, while internal audits invert external reconnaissance techniques against one’s own assets to surface residual risks such as identity gaps, multi-tenant noise, and clone feedstock.

Quantitative Security, exemplifies this model in practice. The firm builds and runs the same enrichment and prioritization pipelines used in real threat-hunting environments, reducing large volumes of noisy telemetry to clear, attributed, ranked targets. Tools such as the QuantSec SpamLink Intelligence Extractor (QS-SLIE) convert spam chaos into structured intelligence—full forensic HTML archives, domain/link graphs, blocklists, and high-priority alerts—feeding automated email-threat pipelines. Live sensors QuantC and QuantumGuard support correlation during self-recon and protective operations. Structured protective-intelligence reports produced from these systems have been shared both publicly as TLP:CLEAR long-form articles and directly with federal agencies. Mid-year reviews document the progression from foundational command-center tooling and defensive innovation in Q1 2026 to scaled public education and matured automated pipelines in Q2, establishing the operational tempo required for high-fidelity protective intelligence at scale.

This capability path aligns directly with recent federal initiatives. A major expansion of the U.S. government’s approach to cybercrime, formalized in an August 2026 presidential action, brings selected private cybersecurity companies into government-directed offensive and intelligence operations against transnational cyber-enabled crime. Complementary efforts include expanded CISA threat-hunting operational support, Treasury sharing of cybersecurity threat intelligence with digital-asset and critical-infrastructure firms, and public-private collaborations that have already seized tens of millions in scam proceeds. Quantitative Security’s demonstrated ability to produce attributed, prioritized intelligence products, conduct self-directed residual-risk mapping, and operate enrichment pipelines positions on the trajectory toward participation in these federal contracts and partnerships—particularly those focused on disrupting both criminal networks and nation-backed campaigns.

These measures, combined with arrests such as the one following the John Daghita mapping and ongoing freezes from nation-backed cases, demonstrate prioritization of accountability across the hierarchy. Separating criminal capability levels by observed tactics and dollar impact from true nation-backed operations, while elevating the classic-hacker model of pure exposure and the practical threat-hunting work of firms such as Quantitative Security, removes prestige from low- and mid-tier scammers, clarifies the distinct scale of state-directed activity, and highlights the clean, truth-oriented, federally aligned work that strengthens national defenses. Public mapping of the cases above, together with ongoing protective-intelligence briefs published through quantitativesecurity.org supplies concrete reference points for education, prevention, and policy.

Next
Next

Internal Audit as External Threat Hunter - Quant. Sec.