Advanced persistent threat (APT) refers to attacker groups operating with substantial resources, a clear mandate and a long breath — often state-sponsored or tolerated. Their hallmark is not a particular tool but the way of working: deliberate victim selection, quiet operations, months of presence.
Unlike opportunistic crime, an APT chooses its target consciously: technology, research, critical infrastructure, suppliers with access to bigger targets. The defensive ambition thus shifts from preventing to detecting and containing.
How do APT groups operate?
Entry often happens via spear phishing, supply chains or fresh vulnerabilities in edge systems — VPN gateways and other exposed infrastructure are favourites. Then follows the phase that distinguishes APTs: inconspicuous spread using legitimate tools (living off the land), creating multiple access paths, patience. Many groups stay undetected for months because they behave like administrators.
Defence therefore relies on behaviour instead of signatures: anomalies in identities and east-west traffic, hardened edge systems, segmentation as a movement brake — and the assumption that prevention alone is not enough.
What really helps against APTs
- Attack surface hygiene: minimise exposed systems and patch consistently.
- Phishing-resistant authentication and a strict privilege concept.
- Segmentation and Zero Trust access as a structural movement brake.
- Behaviour-based detection (EDR, NDR) plus rehearsed incident response.