Mastodon Mastodon Mastodon Mastodon

Advanced Persistent Threat

Updated: · CyberSecureFox Editorial Team

An advanced persistent threat (APT) is a well-resourced, usually state-sponsored group that carries out long-term, targeted cyber operations to spy, steal data or sabotage.

How APT groups operate

The term was used by the US Air Force around 2006 and became widely known after Mandiant’s 2013 report on the Chinese unit APT1. “Advanced” refers to skills and tools, “persistent” to the patience of staying inside a network for months or years. A typical campaign includes:

Why APTs matter for security

APT groups target governments, defence, energy, telecom, research and tech companies, but also NGOs and journalists. Security vendors give them names and numbers: APT28 (Fancy Bear) and APT29 (Cozy Bear) are linked to Russia, APT41 and Volt Typhoon to China, Lazarus to North Korea – which in February 2025 stole about $1.5 billion in cryptocurrency from the Bybit exchange. Some groups mix espionage with financial crime. Because they adapt to defences, simple signature-based protection is not enough.

How to defend

  • Patch and harden internet-facing devices – VPN, firewalls, mail servers – which APTs attack first.
  • Use threat intelligence and the MITRE ATT&CK knowledge base to understand relevant groups and techniques.
  • Collect logs centrally, keep them long enough, and hunt for threats proactively.
  • Apply phishing-resistant MFA, segmentation and least privilege.
Synonyms:
APT group, APT groups