Because the same techniques produce the same operational effect, regardless of motive. Credential theft, proxying, supply-chain abuse, and living off the land all let attackers blend into normal enterprise activity. That means defenders get more value from blocking capability than from trying to classify intent before action is taken.
Why defenders see the same playbook on both sides
Cybercrime and cyberwarfare converge because modern intrusion tradecraft is judged by access and impact, not by motive. Once an actor can steal credentials, proxy through legitimate infrastructure, abuse suppliers, or run commands inside ordinary admin tooling, the defender sees the same telemetry patterns either way. That is why response teams increasingly focus on capability, dwell time, and blast radius rather than trying to infer intent from the first artifact alone.
That similarity is also reinforced by MITRE ATT&CK Enterprise, which helps defenders map credential access, lateral movement, and privilege escalation even when the campaign is financially motivated or politically motivated. The practical lesson is that the initial control problem is often identical: stop the technique, contain the access, and then attribute the campaign.
At the same time, defenders are watching an expanding set of access paths that look ordinary at first glance. A stolen token, a compromised service account, or a trusted third-party relationship can all produce traffic that appears operationally valid until the misuse becomes obvious. For that reason, CISA cyber threat advisories remain useful because they highlight how real-world intrusion patterns repeatedly rely on the same authentication and living-off-the-land behaviors across many campaigns.
Why motive matters less than observed technique
Defenders do not get a clean separation between crime and warfare at the network layer because many of the enabling methods are commodity. A phishing chain, reused password, remote access proxy, malicious update, or abused cloud credential can be purchased, rented, stolen, or assigned by a state sponsor. The observable effect is the same: unauthorized access that blends into normal business operations long enough to matter.
The most important shift is that the attacker’s objective may differ, but the operational constraints do not. Criminals want monetization; state actors may want espionage, pre-positioning, disruption, or coercive access. Yet both still need stealth, persistence, and lateral movement, which pushes them toward familiar techniques such as valid accounts, trusted software paths, and borrowed infrastructure. That convergence is why defenders get more value from control effectiveness than from labeling the adversary too early.
When the same infrastructure and techniques keep recurring, it is also worth watching the underlying exploitability of exposed systems. The CISA Known Exploited Vulnerabilities Catalog is relevant because active exploitation often becomes the bridge between opportunistic criminal abuse and higher-end operational campaigns. If an externally reachable weakness is being abused at scale, the defender’s response usually needs to be capability-led, not motive-led.
What this means for detection and response
Because the external shape of the attack looks similar, detection should prioritize reliable signals of misuse, not assumptions about who is behind the screen. Excess privilege, abnormal token use, impossible travel, suspicious process chains, lateral movement from valid sessions, and unusual access through trusted vendors all deserve faster action than narrative-based classification. In practice, the stronger the masquerade, the more the defender must lean on control points that are hard to fake.
This is also where cloud, identity, and endpoint telemetry need to be correlated. A single login event may look harmless; the same login plus unusual file access, remote command execution, and outbound staging traffic is a materially different story. The right question is not “is this crime or war?”, but “what capability is being exercised, from where, and how far can it move?”
For infrastructure teams, that usually means treating CISA Secure by Design principles as part of the detection problem, not just the build problem. Products and services that reduce default trust, remove unnecessary privilege, and limit exposed pathways make it harder for either criminal or state-backed operators to blend in once they arrive.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1003 — OS Credential Dumping | Credential theft is central to how both crime and war campaigns obtain valid access. |
| T1078 — Valid Accounts | The question centers on abuse of legitimate access that hides attacker intent. | |
| Recommendation — Map credential-theft activity to T1003 and hunt for reuse of stolen identities across hosts. Treat valid-account use as a priority detection path and tighten monitoring on privileged sessions. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Enforcement | The answer depends on preventing and constraining valid-access abuse. |
| Recommendation — Enforce least-privilege access and strong authentication for accounts that can reach critical systems. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account abuse and reuse are common to both criminal and state-backed intrusion chains. |
| Recommendation — Review and disable unnecessary accounts, then remove stale access that can be reused by intruders. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential theft and token abuse are core mechanisms behind the similarity described. |
| Recommendation — Rotate and protect authenticators so stolen credentials cannot be reused for long. | ||
Practitioner Guidance
What to prioritise: Focus first on controls that reduce valid-access abuse, because those are the common denominator across crime and warfare. If an attacker can authenticate, reuse trust, or move through approved tooling, motive is already less important than containment.
What to verify: Check whether your detection stack can distinguish ordinary administrative behavior from stolen-session behavior, third-party abuse, and living-off-the-land execution. If those cases collapse into the same alert bucket, defenders will stay behind the attacker’s speed.
Common mistake: Teams often over-invest in attribution and under-invest in blast-radius reduction. The more useful operational split is not “criminal versus state”, but “blocked, contained, or still able to pivot”.
Practitioner takeaway: The defender’s advantage comes from denying reusable capability, not from guessing intent early, so design your controls around observable misuse, constrained privilege, and fast containment.
Related resources from NHI Mgmt Group
- How should security teams respond when cybercrime and cyberwarfare use the same TTPs?
- How should defenders respond when cybercrime groups rebrand but keep the same infrastructure?
- How should security teams handle insider threat cases when compromise and employee misuse look similar?
- How should organisations classify automated traffic when AI agents and bots look similar?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org