An advanced persistent threat (APT) is an attacker, usually an organized group, with the skill, resources and patience to target specific organizations and stay hidden inside their networks for weeks, months or longer. “Advanced” refers to the attacker’s capability, “persistent” to their long-term goal of keeping access, and “threat” to the group itself. Many APT groups are linked to nation-states and pursue espionage or disruption, though the term is also applied to well-organized criminal groups that operate the same way.
At a glance
- APT describes a type of attacker, not a specific piece of malware or a single attack.
- APT groups pick their targets deliberately and work to keep long-term, quiet access.
- They often rely on stolen credentials and legitimate admin tools, which makes them harder to spot than commodity malware.
- Suppliers and service providers can be targeted as a route into larger organizations.
- Defending against them depends on detection across many data sources and people who investigate, not just on blocking at the perimeter.
What problem it solves
As a term, APT helps buyers and security teams separate two different kinds of risk. Most attacks are opportunistic: automated scans and mass phishing that hit whoever is vulnerable and try to profit quickly. An APT is different. It has chosen you, or a customer of yours, and will try again if the first attempt fails.
That difference changes what good defense looks like. Opportunistic attacks are largely stopped by basics such as patching, multi-factor authentication and endpoint protection. A determined, well-resourced attacker may get past those eventually, so the question becomes how quickly you notice them once they are inside and how well you can contain them. Knowing which groups target your industry, and how they operate, also helps prioritize where to spend.
How it works
APT intrusions vary, but they commonly follow a pattern that security teams describe in stages.
Initial access. Targeted phishing, exploiting a vulnerable internet-facing system, stolen credentials or compromising a supplier with trusted access, as in a supply chain attack.
Establishing a foothold. Installing a way back in, such as a hidden remote access tool, or creating accounts that look legitimate.
Lateral movement. Moving from the first system to others, gathering credentials and escalating privileges, often using the same tools administrators use so the activity blends in.
Achieving the goal. Collecting and quietly sending out data, or positioning for disruption. The longer the dwell time, the more an attacker can do.
Persistence. Keeping multiple ways in so that cleaning one system doesn’t remove them.
Security teams describe the specific methods a group uses as its tactics, techniques and procedures (TTPs), and track groups through cyber threat intelligence (CTI).
When it matters for buyers
- When you serve government, defense, critical infrastructure or regulated industries. Customers may ask how you would detect a targeted intrusion, and contracts can carry security requirements.
- When you hold data or access others want. Intellectual property, customer networks you manage, or financial and legal information make an organization a target.
- When choosing detection and response services. Ask how the provider detects attackers using legitimate tools and valid accounts, not just known malware. Our managed detection and response overview explains what these services cover.
- When a peer or supplier is breached. A group that hit a partner may use that access, or similar methods, against you.
- When deciding whether to invest in threat hunting. Hunting assumes some attackers get past alerts, which is the APT scenario.
Questions to ask vendors
- How do you detect attackers who use valid credentials and built-in admin tools rather than malware?
- Which data sources do you correlate: endpoints, identity, email, cloud, network?
- Do you hunt proactively, how often, and is it included or extra?
- How do you use threat intelligence about groups targeting our industry?
- What is your process when you find evidence of long-term compromise, and when does incident response take over?
- How do you map your detections to known attacker techniques, and can you show where we have gaps?
How it differs from commodity malware and ransomware
Commodity malware and most ransomware campaigns are opportunistic: the attacker casts a wide net, uses widely available tools and wants a quick payoff. An APT is defined by targeting and patience rather than by a particular tool. The practical difference for a buyer is that defenses aimed at known malware may not catch an APT using legitimate software and stolen accounts. The overlap is real, though: some criminal ransomware groups now spend time inside a network before striking, and some state-linked groups use ransomware, so detection should cover both behaviours.
