An advanced persistent threat (APT) is a well-resourced, usually state-sponsored group that carries out long-term, targeted cyber operations to spy, steal data or sabotage.
How APT groups operate
The term was used by the US Air Force around 2006 and became widely known after Mandiant’s 2013 report on the Chinese unit APT1. “Advanced” refers to skills and tools, “persistent” to the patience of staying inside a network for months or years. A typical campaign includes:
- careful reconnaissance and spear phishing or exploitation of edge devices, sometimes with zero-days;
- custom malware, backdoors and use of legitimate admin tools to stay hidden;
- lateral movement to high-value systems and slow, quiet data exfiltration;
- supply chain attacks to reach many targets at once.
Why APTs matter for security
APT groups target governments, defence, energy, telecom, research and tech companies, but also NGOs and journalists. Security vendors give them names and numbers: APT28 (Fancy Bear) and APT29 (Cozy Bear) are linked to Russia, APT41 and Volt Typhoon to China, Lazarus to North Korea – which in February 2025 stole about $1.5 billion in cryptocurrency from the Bybit exchange. Some groups mix espionage with financial crime. Because they adapt to defences, simple signature-based protection is not enough.
How to defend
- Patch and harden internet-facing devices – VPN, firewalls, mail servers – which APTs attack first.
- Use threat intelligence and the MITRE ATT&CK knowledge base to understand relevant groups and techniques.
- Collect logs centrally, keep them long enough, and hunt for threats proactively.
- Apply phishing-resistant MFA, segmentation and least privilege.