Skip to main content
QUIETLYTIC
Analysis

Who Are State-Sponsored Hackers? A Complete Guide

What state-sponsored hackers are, which governments run them, their motivations, and how they differ from cybercriminals — grounded in DOJ, CISA, and MITRE ATT&CK.

Who Are State-Sponsored Hackers? A Complete Guide — Analysis research

State-sponsored hackers are individuals or groups conducting cyber operations on behalf of, or with the acknowledged support of, a national government — as opposed to cybercriminals acting purely for personal profit or hacktivists acting on their own political motivations. The U.S. government doesn’t use the term casually: DOJ indictments, CISA advisories, and Treasury sanctions each represent a formal, evidence-based attribution process, not a guess. This guide covers who these actors are, which governments run them, why they operate, and how their tactics differ from ordinary cybercrime.

How governments formally attribute a hacking group

Attribution isn’t a single vendor’s opinion — it typically layers three types of evidence. DOJ indictments name specific individuals and, where the evidence supports it, tie them to a government body (a 2021 DOJ indictment affirmatively connected named hackers to North Korea’s Reconnaissance General Bureau, the group publicly known as Lazarus Group). CISA cybersecurity advisories, often issued jointly with the FBI, NSA, or international partners, describe a group’s tactics, techniques, and indicators of compromise without necessarily naming individuals. Treasury’s Office of Foreign Assets Control (OFAC) sanctions a group or its infrastructure once financial evidence ties it to a government — OFAC first sanctioned Lazarus Group and its sub-groups in 2019. Not every group carries the same level of certainty: some, like APT28, are tied to a specific military unit (Russia’s GRU); others, like APT41, are described by DOJ as receiving only “tacit” state support rather than being direct government employees.

Why governments sponsor hacking operations

Four motivations recur across nearly every documented state-sponsored campaign:

  • Espionage. Stealing state secrets, intellectual property, or diplomatic communications to gain strategic advantage — this is the primary driver behind groups like APT29, whose intrusion into SolarWinds’ software supply chain gave it access to numerous U.S. federal agencies.
  • Disruption and sabotage. Attacks meant to degrade an adversary’s infrastructure or capabilities, sometimes as a substitute for or precursor to conventional conflict — CISA’s advisories on Russian GRU-linked Sandworm Team document destructive malware deployed against Ukraine’s power grid.
  • Pre-positioning. A newer, distinct objective: quietly establishing persistent access inside critical infrastructure for potential future use rather than immediate disruption — this is the pattern CISA has documented with Volt Typhoon inside U.S. critical infrastructure networks.
  • Financial gain. Historically the domain of cybercriminals, but North Korea has blended espionage tradecraft with outright theft — CISA, the FBI, and Treasury jointly documented Lazarus Group-linked actors stealing cryptocurrency to fund state programs under sanctions evasion pressure.

How state-sponsored hackers differ from cybercriminals

The distinction matters operationally, not just semantically. A ransomware gang wants to be paid quickly and moves on; a state-sponsored group tied to espionage often wants to stay undetected for months or years, prioritizing stealth over speed. Cybercriminal groups are opportunistic about targets — whoever’s vulnerable. State-sponsored groups are frequently strategic about targets, aligned with their sponsor’s geopolitical interests: defense contractors, government agencies, dissidents, or a specific sector under sanctions pressure. And resourcing differs sharply — a state-sponsored group can draw on custom-built malware, zero-day exploits, and sustained multi-year operations that most criminal groups can’t fund on their own. This is also why the two categories increasingly overlap: North Korea’s cryptocurrency theft operations use nation-state tradecraft in service of what looks, on the surface, like ordinary financially motivated crime.

Where MITRE ATT&CK fits in

MITRE ATT&CK, the publicly maintained taxonomy of adversary tactics and techniques developed with DHS/CISA sponsorship, is how the security industry describes what a state-sponsored group actually does at a technical level — not who sponsors it, but how it operates: which initial access methods it favors, how it moves laterally, what it does to maintain persistence. It’s the common reference this site’s own threat-actor profiles are built on, and it’s why a group’s ATT&CK technique IDs are worth checking directly rather than relying on a narrative summary — our ATT&CK technique lookup resolves any technique ID against MITRE’s own dataset in the browser.

Groups worth knowing by name

Four groups come up in nearly every U.S. government advisory on this topic: APT28 (Russia’s GRU, also known as Fancy Bear), APT29 (Russia, also known as Cozy Bear, behind the SolarWinds compromise), Lazarus Group (North Korea’s RGB), and APT41 (China, blending state espionage with financially motivated intrusions). For the full list this site tracks and profiles in detail — including Sandworm Team, Volt Typhoon, and Kimsuky — see our threat actors hub, and for a deeper look at the seven most active groups currently targeting U.S. organizations, see our roundup of the most dangerous state-sponsored hacker groups.

Frequently Asked Questions

What makes a hacking group “state-sponsored” rather than just a cybercriminal gang? Formal government attribution — a DOJ indictment tying named individuals to a government body, a CISA advisory documenting the group’s activity, or Treasury sanctions — not just a vendor’s naming convention or a researcher’s suspicion.

Do state-sponsored hackers ever act like ordinary cybercriminals? Yes — North Korea’s Lazarus Group is the clearest example, using nation-state tradecraft to steal cryptocurrency for the state rather than pure espionage, blurring the line between the two categories.

How many countries run state-sponsored hacking operations? U.S. government advisories most frequently attribute activity to Russia, China, North Korea, and Iran, though CISA and allied agencies have documented state-linked activity from additional countries as evidence has developed.


Grounded in DOJ indictments, CISA cybersecurity advisories, and MITRE ATT&CK. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 MITRE ATT&CK
02 U.S. Department of Justice (DOJ)
03 Cybersecurity and Infrastructure Security Agency (CISA)

Related intelligence


Cross-referenced intelligence


Analyst tools