Advanced Persistent Threat (APT)
Definition
A category of attacker, typically nation-state or state-sponsored, characterised by high technical capability, long dwell times, specific targets, and disciplined operational security. Named APT groups (e.g. APT28, APT41) are tracked by threat intelligence vendors and government agencies.
- Typical sponsor
- Nation-state or state-sponsored
- Hallmark
- Long dwell time before detection
- Naming examples
- APT28, APT41
- Tracked by
- Threat intelligence vendors, government agencies
Common questions
What separates an APT from an ordinary cybercriminal intrusion?+
An APT actor pursues a specific, often strategic target over an extended period with disciplined operational security to avoid detection, rather than opportunistically compromising whatever system is easiest to reach.
Why do different vendors sometimes assign different names to what looks like the same group?+
Each vendor tracks the actor through its own visibility and evidence, so naming reflects that vendor's cluster of observed indicators, and two names can later turn out to describe overlapping or identical activity.
Related terms
- Insider Threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Threat Actor
- An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...
- Threat Intelligence
- Processed, analysed information about adversaries, their capabilities, and their current or anticipated activities. Includes strategic intelligence (actor motivations and trends) and tactical...
- Threat Vector
- The pathway or method a threat actor uses to gain access or cause harm. Examples include phishing email, unpatched software vulnerabilities, compromised...