Glossary · simply explained

APT (Advanced Persistent Threat)

Advanced persistent threat (APT) refers to attacker groups operating with substantial resources, a clear mandate and a long breath — often state-sponsored or tolerated. Their hallmark is not a particular tool but the way of working: deliberate victim selection, quiet operations, months of presence.

Unlike opportunistic crime, an APT chooses its target consciously: technology, research, critical infrastructure, suppliers with access to bigger targets. The defensive ambition thus shifts from preventing to detecting and containing.

How do APT groups operate?

Entry often happens via spear phishing, supply chains or fresh vulnerabilities in edge systems — VPN gateways and other exposed infrastructure are favourites. Then follows the phase that distinguishes APTs: inconspicuous spread using legitimate tools (living off the land), creating multiple access paths, patience. Many groups stay undetected for months because they behave like administrators.

Defence therefore relies on behaviour instead of signatures: anomalies in identities and east-west traffic, hardened edge systems, segmentation as a movement brake — and the assumption that prevention alone is not enough.

What really helps against APTs

  • Attack surface hygiene: minimise exposed systems and patch consistently.
  • Phishing-resistant authentication and a strict privilege concept.
  • Segmentation and Zero Trust access as a structural movement brake.
  • Behaviour-based detection (EDR, NDR) plus rehearsed incident response.

Frequently asked questions about APT (Advanced Persistent Threat)

What makes an attack an APT attack?

The combination of target selection, resources and persistence: the victim is chosen deliberately, access is held for months, the approach stays quiet. The tools used can be mundane — the way of working is not.

Does the APT topic concern the mid-market too?

Yes — often as a detour: suppliers, service providers and niche market leaders are attractive springboards to bigger targets or hold valuable know-how themselves. Hidden champions in particular regularly underestimate their attractiveness.

What does living off the land mean?

Attackers use the system’s own tools — administration utilities, scripting languages, legitimate remote maintenance — instead of their own malware. That bypasses signature-based detection; such attacks only stand out through behaviour and context.

How long do APTs stay undetected?

Industry reports regularly cite dwell times of weeks to months; longer in poorly monitored environments. Every week of undetected presence increases damage and cleanup effort — which is why detection capability counts more than any single wall.

Where do names like APT28 or Lazarus come from?

Security firms assign catalogue names to observed groups — numbers, animals, mythology. The same group carries several names depending on the vendor. For defenders the name matters less than the documented behaviour, for example in MITRE ATT&CK.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.