What Is an Advanced Persistent Threat (APT)? Guide to APT Groups, Attacks & Nation-State Actors

Knowledge Hub
Advanced Persistent Threat

An advanced persistent threat (APT) is a prolonged, targeted cyberattack in which an intruder, usually a nation-state or state-sponsored group, gains unauthorized access to a network and stays hidden inside it for weeks, months, or years to steal data rather than cause immediate damage. Unlike a smash-and-grab ransomware hit or a mass phishing campaign, an APT is patient by design: the attacker’s goal is sustained access, not a quick payout.

That patience is measurable. According to Mandiant’s M-Trends 2026 report, the median dwell time for cyber espionage intrusions, the hallmark behavior of an APT, reached 122 days in 2025, and some campaigns have gone undetected for nearly 400 days. For context, that’s four to thirteen times longer than the 14-day median dwell time across all intrusion types, which is exactly what separates an APT from ordinary cybercrime: most attackers want in and out fast; APT groups want to stay.

This guide breaks down what defines an APT, how these attacks actually unfold, the major APT groups tracked by researchers today, organized by numbered designation and by the country believed to be behind them, and what detecting and defending against one really requires.

What Is an Advanced Persistent Threat (APT)?

An advanced persistent threat (APT) is a category of cyberattack defined by three traits packed into its name: it uses advanced techniques to break in and evade detection, it maintains a persistent foothold inside the target network over time, and it poses a serious threat because the intent is usually espionage, sabotage, or long-term data theft rather than a one-time payout. The term describes both the attack methodology and, informally, the group carrying it out.

APT Meaning in Cybersecurity

In cybersecurity, “APT” refers to a sustained intrusion campaign carried out by a skilled, well-resourced adversary, most often a government intelligence service or a group operating with state backing. The label isn’t about a single exploit or piece of malware; it describes an entire operation built around gaining access to a network, evading detection, and remaining there to achieve a strategic objective, whether that’s stealing intellectual property, monitoring communications, or positioning for future disruption. Security researchers use “APT” as shorthand for the actor behind the campaign as much as for the campaign itself, which is why you’ll see groups referred to directly as “the APT” or by a specific designation like APT29 or APT41.

How an APT Differs From a Regular Cyberattack

A regular cyberattack- a phishing scam, a smash-and-grab ransomware hit, an opportunistic malware infection- is built for speed: get in, extract value, get out, often within hours. An APT inverts that logic entirely. The attacker deliberately slows down after gaining access, using legitimate credentials and built-in system tools to blend in with normal network traffic rather than deploying obvious malware that might trigger an alert. Where a typical breach is a single event, an APT is an ongoing campaign, sometimes managed by a team that adapts its tactics over months as the target’s defenses change. This is also what separates an APT from a generic “threat actor”; every APT is a threat actor, but most threat actors (a lone scammer, a low-skill botnet operator) never operate with the resourcing, patience, or objectives that define an APT.

Key Characteristics of an APT

Four characteristics recur across APT campaigns: sponsorship, stealth, patience, and specificity. Sponsorship means access to funding, custom tooling, and skilled personnel that most cybercriminals don’t have, a hallmark of nation-state backing. Stealth means minimizing footprint; CrowdStrike’s 2026 Global Threat Report found that 82% of intrusions it investigated in 2025 involved no malware at all, with attackers instead relying on valid stolen credentials and trusted system tools to move undetected, a technique especially common among APT-grade actors. Patience is the defining trait; APTs are built to dwell, not to strike and vanish. And specificity means the target is chosen deliberately: a government agency, a defense contractor, a telecom operator, or a company holding data valuable enough to justify the investment. When these four traits show up together, that’s the signature of an APT rather than routine cybercrime.

How APT Attacks Work

An APT attack unfolds in stages rather than a single strike: attackers first break in and establish a foothold, then quietly expand their reach across the network, and finally settle in to extract data or intelligence over an extended period. Each stage is designed to avoid triggering alerts, which is why the full lifecycle can stretch from weeks to years before anyone notices.

How APT Attacks Work

Initial Access and Gaining a Persistent Foothold

Most APT campaigns start the same way ordinary attacks do: spear-phishing emails, exploited software vulnerabilities, compromised third-party vendors, or stolen credentials purchased on the dark web, but what happens immediately after differs. Rather than acting on that access right away, the attacker’s priority is persistence: installing backdoors, creating hidden accounts, or planting web shells so they can return even if the original entry point is discovered and closed. Mandiant’s M-Trends 2026 report found that exploited vulnerabilities remained the leading initial infection vector for the sixth straight year, accounting for 32% of intrusions, with voice phishing overtaking email phishing as attackers shift toward more interactive social engineering to gain that first foothold. Once that foothold is secure, the attacker can afford to move slowly, because the goal isn’t a quick win; it’s guaranteed return access.

Command and Control, Lateral Movement

With a foothold established, the attacker sets up command-and-control (C2) infrastructure. This channel lets them issue instructions to compromised systems and exfiltrate data, often disguised as legitimate web traffic to slip past network monitoring. From there, the operation shifts to lateral movement: using stolen credentials and built-in administrative tools to hop from the initial compromised device to higher-value systems, escalating privileges along the way until the attacker controls accounts with broad access to the network. This phase is deliberately unhurried and low-noise, favoring legitimate tools already present on the network over custom malware that might get flagged. It’s also where APT tradecraft is most visible to defenders who know what to look for: unusual account behavior, off-hours logins, or administrative tools being used in ways that don’t match normal IT activity.

Long-Term Espionage and Exfiltration Goals

The final and longest phase is why the “persistent” in APT matters most: once attackers have the access and positioning they need, they settle in to collect intelligence, monitor communications, or stage data for extraction over an extended period, often returning repeatedly rather than taking everything at once. This is what separates APT-driven espionage from ransomware or theft-focused cybercrime; the objective is sustained visibility into a target, not a single payday. That patience shows up clearly in the numbers: Mandiant recorded a median dwell time of 122 days for cyber espionage intrusions in 2025 and identified campaigns using malware such as BRICKSTORM that went undetected for nearly 400 days, well beyond the 90-day log retention window many organizations rely on. By the time exfiltration is discovered, the attacker has often already achieved months of undisturbed access to exactly the systems they came for.

Types of Advanced Persistent Threats

Advanced persistent threats fall into three broad categories based on who’s behind them and why: state-sponsored groups pursuing geopolitical or espionage goals, criminal organizations chasing financial gain with APT-level sophistication, and hacktivist-aligned actors combining ideological motives with persistent access techniques. The tactics often overlap, but the underlying objective- intelligence, money, or influence- shapes how each type operates.

Types of Advanced Persistent Threats

State-Sponsored (Nation-State) APTs

State-sponsored APTs are groups that operate with the funding, direction, or tacit approval of a national government, and they represent the largest and best-documented share of tracked APT activity. Their objectives typically center on intelligence gathering, political influence, or positioning inside critical infrastructure for potential future disruption, stealing defense research, monitoring dissidents, or maintaining quiet access to power grids and telecom networks rather than cashing out immediately. This is the category that most well-known numbered groups (like APT28 or APT41) and country-attributed clusters (Chinese, Russian, Iranian, and North Korean APT groups) fall into, which is why nation-state attribution has become a standard part of how researchers classify and name these actors. The U.S. Office of the Director of National Intelligence’s 2026 Annual Threat Assessment identified PRC-linked actors as the most persistent cyber threat facing the United States, reflecting how central state sponsorship has become to the modern APT landscape.

Criminally Motivated APT Groups

Not every APT works for a government; a growing subset applies the same patience and tradecraft to purely financial objectives, blurring the line between nation-state espionage and organized cybercrime. These groups behave like APTs in method (persistent access, careful lateral movement, low-noise tooling) but like criminal enterprises in motive, often functioning as initial access brokers who breach a network and then sell that access to ransomware affiliates rather than exploiting it themselves. That handoff has become remarkably fast: Mandiant’s M-Trends 2026 report found the median time between an initial access broker gaining a foothold and handing it off to a ransomware operator dropped to just 22 seconds in 2025, down from more than eight hours in 2022, a sign that financially motivated APT-style operations have industrialized into a coordinated supply chain rather than the work of a single actor.

Hacktivist-Aligned Persistent Threats

A smaller but increasingly active category blends ideological or political motivation with APT-grade persistence, rather than the smash-and-grab defacements typically associated with hacktivism. These actors, sometimes operating independently, sometimes with loose ties to a state’s interests without formal sponsorship, maintain long-term access to targets aligned with a cause: government agencies, media outlets, or organizations tied to a geopolitical conflict. The distinction from state-sponsored APTs lies in attribution and control: hacktivist-aligned groups may share tooling or even infrastructure with nation-state actors, but they act with more autonomy. They are typically driven by public messaging or disruption, alongside or instead of quiet intelligence collection.

Complete List of Known APT Groups

There is no single master list of APT groups because different security vendors track and name overlapping activity independently, but three naming systems dominate the field: Mandiant’s sequential “APT” numbering, MITRE’s ATT&CK group catalog, and vendor-specific naming schemes such as CrowdStrike’s animal-based names and Microsoft’s weather-themed taxonomy. Cross-referencing these systems is often the only way to confirm that “APT28,” “Fancy Bear,” and “Sofacy” all describe the same actor.

Complete List of Known APT Groups

FireEye/Mandiant Numbered Groups (APT1–APT45)

Mandiant (formerly FireEye) pioneered the sequential APT numbering system, assigning a designation like APT1 or APT28 only after enough confirmed, sustained activity ties a cluster of intrusions to a single actor, a bar deliberately set high enough that not every tracked threat cluster earns a number. As of the group’s most recent designation, APT45, the list runs to over 40 named groups, spanning multiple countries: APT1 (China, PLA Unit 61398), APT28 and APT29 (Russia), APT33 and APT34 (Iran), APT38 (North Korea), and APT41 (China, notable for running both espionage and financially motivated operations from the same infrastructure). The two newest entries as of 2024 illustrate how the system evolves: APT44 is the formal designation for the Russian military intelligence-linked group long known as Sandworm, and APT45 elevated the North Korean group previously tracked as Andariel after Mandiant observed it expanding from espionage into ransomware.

MITRE, CrowdStrike & Microsoft Naming Conventions

Outside Mandiant’s numbering, three other systems are widely referenced. MITRE ATT&CK catalogs groups by their most commonly used alias and maps each one to the specific tactics and techniques it’s been observed using, making it the reference point most security teams use for defense planning rather than attribution. CrowdStrike assigns two-word names built from an adjective and an animal tied to the actor’s suspected origin; Chinese-nexus actors get “Panda” (Mustang Panda), Russian-nexus actors get “Bear” (Cozy Bear, for the group Mandiant tracks as APT29), and Iranian-nexus actors get “Kitten.” Microsoft moved to a weather-based system in 2023, naming state actors after storm types by country of origin; Chinese groups are “Typhoon” (Salt Typhoon, Volt Typhoon), Russian groups are “Blizzard,” and North Korean groups are “Sleet.” The result is that a single group can carry four or five different names across reports, which is exactly why cross-referencing matters when researching a specific actor.

Notable Named Groups (Lazarus, Turla, Sandworm, Salt Typhoon…)

A handful of groups have become widely recognized under a single common name, regardless of which vendor reports them. Lazarus Group, attributed to North Korea, is responsible for some of the most damaging attacks on record, including the 2014 Sony Pictures breach and years of cryptocurrency theft funding the regime. Turla, one of Russia’s oldest known cyber espionage operations, has been active since at least the mid-2000s and is known for exceptionally stealthy, long-running campaigns against governments and diplomatic targets. Sandworm (APT44), also known as Russia, is distinguished by its willingness to cause physical disruption; it has been tied to attacks that cut power to hundreds of thousands of people in Ukraine and to the NotPetya malware, which caused an estimated $10 billion in global damage. Salt Typhoon, a more recent Chinese-nexus group, drew significant attention for embedding itself inside major U.S. telecommunications providers, with reporting indicating it maintained undetected access inside at least one carrier’s network for roughly three years before discovery, a case study in exactly how long “persistent” can mean in practice.

APT Groups by Country and Region

APT groups are most often organized by suspected country of origin, since attribution to a specific government or intelligence service is usually the strongest signal researchers have for grouping related activity. Four countries, China, Russia, Iran, and North Korea, account for the large majority of tracked, named APT groups. However, state-linked activity has been attributed to several other nations as well.

APT Groups by Country and Region

Chinese APT Groups

Chinese APT groups are generally assessed to operate in support of Beijing’s intelligence services or military, and they represent the largest single bloc of tracked nation-state activity, with a consistent focus on intellectual property theft, telecommunications infrastructure, and long-term positioning inside critical systems. APT1, one of the first groups Mandiant ever formally exposed, was tied directly to a PLA military unit and focused on large-scale IP theft from U.S. companies. APT41 is notable for blending state-directed espionage with financially motivated operations run by the same individuals. More recently, Salt Typhoon and Volt Typhoon have drawn attention for embedding themselves within U.S. telecom and critical infrastructure networks; Volt Typhoon in particular has been reported to maintain undetected access in some victim environments for as long as five years, an extreme example of the “persistent” in APT.

Russian APT Groups

Russian APT groups are typically linked to one of two intelligence services, the GRU (military intelligence) or the SVR (foreign intelligence), and their objectives split between traditional espionage and, in some cases, active disruption or sabotage. APT29 (also known as Cozy Bear), attributed to the SVR, was behind the 2020 SolarWinds supply chain compromise, which reached roughly 18,000 organizations through a single trojanized software update. APT28 (Fancy Bear), linked to the GRU, has been tied to election interference operations since 2016. APT44 (Sandworm), also GRU-linked, stands apart for its willingness to cause physical, real-world disruption, including attacks that cut electricity to hundreds of thousands of people in Ukraine.

Iranian APT Groups

Iranian APT groups are generally assessed to support the Islamic Revolutionary Guard Corps or the Ministry of Intelligence, with activity concentrated on the energy sector, regional adversaries, and dissidents both inside and outside Iran. APT33 (also tracked as Elfin) has focused heavily on the aviation and energy sectors, including destructive attacks against Saudi organizations. APT34 (OilRig) is known for long-running espionage campaigns targeting government and financial institutions across the Middle East. APT35 (Charming Kitten) has repeatedly targeted journalists, academics, and political dissidents through elaborate social engineering rather than technical exploits, reflecting Iran’s broader emphasis on human-focused intelligence operations.

North Korean APT Groups

North Korean APT groups are distinctive because they mix conventional state espionage with financially motivated cybercrime used to fund the regime under international sanctions, a dual mandate rarely seen from other nation-state actors. Lazarus Group, the most well-known, has been linked to the 2014 Sony Pictures hack, the 2017 WannaCry ransomware outbreak, and years of cryptocurrency theft that researchers estimate has generated well over a billion dollars for the North Korean government. APT38 focuses specifically on large-scale financial theft, including attempted bank heists through the SWIFT payment network. APT43 (Kimsuky) runs espionage operations against South Korean and U.S. targets while separately laundering stolen cryptocurrency to fund its own activities, and APT45, elevated from the group formerly tracked as Andariel, marked a rare shift toward ransomware deployment against healthcare and energy targets.

Other Notable State Actors (US, India, Pakistan, Israel)

Nation-state APT activity isn’t limited to the four countries above. The Equation Group, widely assessed by researchers to be linked to U.S. intelligence, has been described as one of the most technically sophisticated actors ever documented, with ties to the Stuxnet operation against Iranian nuclear infrastructure. Indian-linked activity includes groups like SideWinder, focused primarily on regional espionage against Pakistan and other South Asian targets. In contrast, Pakistani-linked groups such as Transparent Tribe have run long-term campaigns against Indian military and government personnel. Israeli-linked capability has been most publicly associated with Stuxnet and Duqu, developed in cooperation with the United States and aimed at slowing Iran’s nuclear program. These cases underscore that APT activity is a global phenomenon shaped by regional rivalries, not just the handful of countries that dominate headline coverage.

Real-World APT Examples and Recent Activity

The clearest way to understand what an advanced persistent threat looks like in practice is through the campaigns that defined the term and those still unfolding, including those from this year. Historical incidents show the scale that APTs can reach; current activity shows the pattern hasn’t slowed.

Landmark Historical APT Attacks

A handful of incidents shaped how the security industry thinks about APTs today. Stuxnet, discovered in 2010 and widely attributed to a joint U.S.-Israeli operation, physically damaged centrifuges at Iran’s Natanz nuclear facility by manipulating industrial control systems, proof that an APT could cause real-world physical destruction, not just steal data. The 2020 SolarWinds compromise, attributed to Russia’s APT29, distributed malware through a trojanized software update that reached roughly 18,000 organizations, including multiple U.S. federal agencies, and remains one of the most consequential supply-chain attacks on record. NotPetya, deployed by Russia’s Sandworm (APT44) in 2017 through compromised Ukrainian accounting software, spread globally and caused an estimated $10 billion in damage, making it the most costly cyberattack in history at the time. And North Korea’s Lazarus Group breached Sony Pictures in 2014 in retaliation for a film, destroying data and leaking internal communications in an operation that blurred the line between espionage and geopolitical coercion.

Recently Disclosed and Active Campaigns (2026)

APT activity hasn’t slowed in 2026; if anything, disclosure has accelerated as researchers get faster at attribution. In January, Russia’s APT28 launched “Operation Neusploit,” exploiting a Microsoft Office zero-day (CVE-2026-21509) within days of discovery to target Ukrainian defense institutions and allied governments, with researchers later uncovering a second zero-day used in the same campaign. In February, a separate China-linked operation compromised more than 50 telecoms and government agencies across 42 countries, hiding its activity inside Google Sheets to blend in with legitimate cloud traffic. Salt Typhoon, the Chinese group behind the 2024 U.S. telecom breaches, remains active inside American networks, with reporting this year confirming fresh access to U.S. House Committee email systems. And in May, the Pakistan-linked group SideCopy ran “Operation Xenofiscal” against Afghanistan’s finance ministry, narrowly targeting provincial tax officials rather than central government, the kind of precise, patient targeting that distinguishes an APT from opportunistic cybercrime. Taken together, these cases confirm the same pattern behind every APT on this list: quiet access, sustained over time, and aimed at a specific, deliberate objective.

How to Detect and Defend Against APT Attacks

Detecting an advanced persistent threat requires a fundamentally different approach from stopping ordinary malware, because APT actors are specifically designed to evade the signatures and alerts that detect conventional attacks. Effective defense combines active threat hunting, layered security practices, and visibility into places most tools don’t look, including the dark web, where early indicators of a compromise often surface first.

How to Detect and Defend Against APT Attacks

APT Detection and Threat Hunting Techniques

Because APT actors favor legitimate credentials and built-in system tools over obvious malware, traditional signature-based detection often misses them entirely, which is why threat hunting has become central to catching APT activity. Effective hunting focuses on behavioral anomalies rather than known malware signatures: unusual login times or locations for privileged accounts, administrative tools being used in ways that don’t match a user’s normal role, unexpected outbound traffic to unfamiliar destinations, and lateral movement between systems that wouldn’t normally communicate. Network segmentation and detailed log retention matter enormously here, since Mandiant’s own research has found that many organizations’ 90-day log retention policies leave them blind to APT campaigns that dwell for nearly 400 days; by the time a hunt begins, the earliest evidence may already be gone. Endpoint detection and response (EDR) tools that flag credential misuse and living-off-the-land techniques, rather than just malware execution, have become the baseline expectation for catching APT-grade activity before it reaches its objective.

Best Practices for APT Protection

No single control stops an APT because these actors are built to bypass any one defense; protection comes from layering measures that make each stage of the attack harder and slower. Multi-factor authentication prevents credential theft and reuse that underpin most initial access and lateral movement. Network segmentation limits how far an attacker can move even after breaching a single system, containing what would otherwise become organization-wide access. Regular patching matters more than most organizations treat it; Mandiant’s data show that exploited vulnerabilities have been the leading initial infection vector for six consecutive years, meaning unpatched software remains the most common open door. Employee awareness training addresses the human side, since spear-phishing and increasingly voice-based social engineering remain primary entry points even as technical defenses improve. And incident response planning, tested before it’s needed, determines whether a detected intrusion gets contained in days or allowed to linger for months.

How Dark Web Monitoring Surfaces Early APT Indicators

Much of the tooling and access APT groups rely on doesn’t stay hidden forever; stolen credentials, breached databases, and initial access being sold to affiliates all tend to surface on dark web markets and forums before or during an active intrusion, which makes dark web monitoring one of the few ways to catch an APT campaign before full damage is done. Continuous monitoring for an organization’s exposed credentials, leaked internal data, or brand impersonation can flag exactly the kind of access that initial access brokers package and sell, the same handoff economy that Mandiant found now moves in a median of 22 seconds once a foothold is established. Platforms like DeXpose apply this by scanning dark web marketplaces, breach dumps, and malware logs for an organization’s exposure, giving security teams a warning signal that a foothold may already exist even before internal detection tools notice anything unusual, closing some of the gap between the months an APT can dwell undetected and the moment a defender actually finds out.

Threat Actor vs. APT: Clearing Up the Terminology

A threat actor is any individual or group responsible for a malicious act against a computer system. In contrast, an advanced persistent threat is a specific, narrower category of threat actor defined by sophistication, sponsorship, and sustained access. Every APT is a threat actor, but the reverse isn’t true, which is exactly the distinction worth untangling before applying either term.

Threat Actor vs. APT

Threat Actor vs. APT vs. Hacking Group

“Threat actor” is the broadest term in cybersecurity, covering anyone from a lone scammer running phishing emails to a well-funded nation-state operation; it describes the who, not the sophistication or intent. “Hacking group” narrows that slightly to organized collectives, which can range from a handful of amateurs to a professional criminal enterprise, but still says nothing about capability or objective. “APT” is the narrowest and most specific of the three: it’s reserved for actors that combine advanced technical capability, sustained persistence inside a target network, and typically state sponsorship or state-level objectives. A useful way to think about it is as a set of nested circles: all APTs are threat actors; some threat actors are organized into hacking groups; but only the most capable, patient, and often government-backed groups earn the APT designation from researchers.

Why Not Every Threat Actor Is an APT

Most threat activity that organizations actually face- mass phishing, commodity ransomware, opportunistic credential stuffing- comes from actors optimizing for speed and volume rather than stealth and patience, which is the opposite of how an APT operates. A criminal group blasting out ransomware to thousands of targets and taking whatever pays out fastest has no interest in dwelling undetected for months; that behavior would slow down their business model. What separates a garden-variety threat actor from an APT isn’t malice or skill alone, but a specific combination of resourcing, discipline, and objective: the willingness to move slowly, avoid detection for extended periods, and pursue intelligence or strategic access rather than an immediate payout. That’s also why the APT label gets applied cautiously by researchers, as covered earlier; Mandiant only assigns a formal APT designation once a cluster of activity has been tied conclusively to a single, sustained actor, which is why only a few dozen groups carry the designation despite thousands of threat actors being tracked industry-wide.

Frequently Asked Questions (FAQ’s)

Is an APT the same as malware?

No. Malware is a tool, a piece of malicious software. An APT is the actor and the campaign built around achieving persistent, undetected access, which may or may not involve custom malware at any given stage.

How long does an APT typically stay inside a network before being discovered?

It varies widely, but industry data has put the median dwell time for cyber espionage intrusions at around four months, with some documented cases stretching close to a year.

Are APTs always government-sponsored?

No. Most tracked APTs are linked to nation-states, but a growing number operate for financial gain, using the same patient, low-noise tradecraft without any government backing.

Can an APT target a small business?

Yes, though less often than large enterprises or government targets. Small businesses are more commonly targeted as a stepping stone, a supplier or vendor with less mature security that provides a path into a larger, higher-value target.

How is a new APT group officially named or numbered?

Security vendors assign a formal designation only after they’ve tied a cluster of activity to a single, distinct actor with enough confidence and history to warrant tracking it as its own entity, rather than folding it into an existing group.

Free Dark Web Report

Keep reading

No results found.