惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Privacy & Cybersecurity Law Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
阮一峰的网络日志
阮一峰的网络日志
Recent Announcements
Recent Announcements
P
Proofpoint News Feed
H
Hacker News: Front Page
H
Help Net Security
云风的 BLOG
云风的 BLOG
H
Heimdal Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
L
Lohrmann on Cybersecurity
C
Check Point Blog
Google DeepMind News
Google DeepMind News
Forbes - Security
Forbes - Security
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
I
InfoQ
The GitHub Blog
The GitHub Blog
The Cloudflare Blog
I
Intezer
L
LINUX DO - 最新话题
K
Kaspersky official blog
Attack and Defense Labs
Attack and Defense Labs
C
CERT Recently Published Vulnerability Notes
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
NISL@THU
NISL@THU
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Vercel News
Vercel News
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Threatpost
Y
Y Combinator Blog
S
Security Affairs
Latest news
Latest news
T
Threat Research - Cisco Blogs
T
Tailwind CSS Blog
C
Cisco Blogs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
P
Privacy International News Feed
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Cisco Talos Blog
Cisco Talos Blog
T
Troy Hunt's Blog
S
Securelist
MongoDB | Blog
MongoDB | Blog

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Stopping Identity Threats with ITDR through MXDR Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs Threat Advisory: Email Account Compromise BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients Partner Spotlight: GoTech IT Solutions Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
Advanced Persistent Threats (APTs) Explained
Nicholas Koken · 2026-02-10 · via Todyl Blog

Advanced Persistent Threats (APTs) represent some of the most dangerous and sophisticated cyberattacks facing organizations today. Unlike opportunistic cybercrime that relies on mass phishing campaigns or commodity malware, APTs are highly targeted, carefully planned, and designed to remain undetected for long periods of time.

As threat actors grow more patient, well-funded, and strategic, the risk is no longer limited to large enterprises or government agencies. Mid-sized organizations and their IT and cybersecurity services partners are increasingly in the crosshairs. For businesses of any size, understanding what APTs are, why they happen, and how attackers operate is a critical first step toward building effective cyber resilience.

What is an Advanced Persistent Threat (APT)?

An Advanced Persistent Threat is a prolonged, targeted cyberattack in which an attacker gains unauthorized access to a network and maintains that access over time. The goal is rarely quick disruption or fast financial gain. Instead, APTs focus on long-term objectives such as espionage, data theft, intellectual property exfiltration, surveillance, or strategic positioning inside a victim’s environment.

While APT campaigns vary widely, they tend to share a few defining characteristics:

  • Highly targeted rather than broad, opportunistic attacks
  • Long dwell time, with attackers remaining undetected for extended periods
  • Custom or adaptive tooling that evolves as defenses change
  • Clear strategic objectives, such as espionage, long-term access, or high-impact extortion

The “advanced” aspect refers to the techniques used: custom malware, zero-day vulnerabilities, living-off-the-land tactics, and carefully crafted social engineering.  

Persistent” reflects the attacker’s intent to maintain access for weeks, months, or even years, adapting their methods as defenses evolve.

Unlike smash-and-grab attacks, APT campaigns often unfold slowly and quietly, making them difficult to detect without continuous monitoring and correlation across endpoints, networks, identities, and cloud workloads.

Why Do APT Attacks Happen? Common Motivations

APTs are driven by objectives that extend beyond simple financial crime. While some financially motivated groups now employ APT-style tactics, many campaigns are rooted in strategic or long-term gain.

One common motivation is espionage. Attackers may seek sensitive business information, trade secrets, research and development data, or confidential communications. This type of activity is especially prevalent in highly competitive industries and geopolitically sensitive sectors.

Another motivation is long-term financial gain. Rather than deploying ransomware immediately, attackers may spend months mapping a network, identifying high-value systems, and positioning themselves for maximum impact. This approach can lead to larger ransom demands, more damaging extortion, or repeated monetization of the same victim.

APTs are also used to enable future attacks. By establishing persistence within one organization, threat actors can pivot into partners, customers, or suppliers. This makes APTs particularly dangerous in interconnected environments and supply chains.

Finally, some APT campaigns are motivated by disruption or influence. These operations may aim to undermine trust, damage reputations, or interfere with operations during critical business periods.

How APT Attacks Work: Tactics and Actions

While every APT campaign is different, most follow a recognizable pattern that aligns with the broader cyber kill chain:

  • Initial access through targeted phishing, credential abuse, or exposed services
  • Establishing persistence within systems and identities
  • Lateral movement to expand access and identify high-value assets
  • Long-term reconnaissance and data collection
  • Execution of the final objective, such as exfiltration, disruption, or extortion

Initial access often begins with highly targeted phishing, credential theft, exploitation of exposed services, or abuse of trusted third-party relationships. Rather than sending thousands of generic phishing emails, attackers research specific individuals and craft believable lures tailored to their roles.

Once inside the environment, attackers focus on establishing persistence. This may involve creating hidden accounts, deploying backdoors, abusing legitimate remote management tools, or embedding themselves in scheduled tasks and services that survive reboots and password changes.

Privilege escalation and lateral movement follow as attackers expand their foothold. They harvest credentials, exploit misconfigurations, and move between systems to map the environment and identify high-value assets.

During the dwell time phase, attackers blend into normal activity. They use legitimate administrative tools, encrypted communications, and low-and-slow techniques to avoid triggering alerts. This is often where the most damage is done, as sensitive data is quietly exfiltrated, or systems are staged for future disruption.

Finally, the attacker executes their end goal. This may involve data theft, ransomware deployment, sabotage, extortion, or coordinated disruption across multiple systems. In many cases, organizations only realize they were victims after this final stage—sometimes months after the initial compromise.

Real-World APT Examples

Often, the term APT is used in conjunction with nation-state actors, but can also describe groups conducting large-scale, targeted operations with specific goals. Through that lens, here are some of the APT groups plaguing today’s organizations:

Akira Ransomware Group

While commonly discussed in the context of ransomware, the Akira group demonstrates many APT-style behaviors, including targeted intrusion, extended reconnaissance within victim environments, and deliberate staging before deploying ransomware and data exfiltration tactics. This reflects a broader trend in which financially motivated threat actors adopt APT tradecraft to increase leverage and impact.

This makes Akira a useful example of how modern APT-style campaigns blur the line between traditional cybercrime and long-term strategic intrusion.

Learn more about Akira in our breakdown of their operation, including their behaviors, tactics, and repeated patterns.

LAPSUS$

The LAPSUS$ group is known for high profile intrusions driven primarily by social engineering rather than custom malware. Their campaigns have leveraged techniques like phishing, MFA fatigue, and identity abuse to gain initial access, followed by rapid privilege escalation and lateral movement to reach sensitive systems. This makes LAPSUS$ a strong example of how modern APT style operations increasingly target people and identity workflows as the most efficient path into otherwise well defended environments, as seen in their campaigns involving Okta and other major platforms.

Find more information about the LASUS$ Okta campaign and how to detect their activity on our blog.

Lazarus Group

The Lazarus Group is widely associated with long running cyber campaigns that blend espionage with financial motivation. Their compromise of 3CX software demonstrated how supply chain attacks can be used to gain broad, downstream access to otherwise well secured environments. By tampering with trusted software updates, Lazarus was able to quietly distribute malware to organizations at scale, reinforcing how APT actors increasingly target vendors and platforms as force multipliers rather than attacking individual companies one by one.

Read our coverage of the Lazarus 3CX attack as one of the first groups to uncover it.

Why APTs Are So Hard to Detect

What makes APTs especially dangerous is not just their sophistication, but their patience. Attackers deliberately avoid noisy techniques that would trigger traditional security alerts. They often rely on legitimate system tools, trusted user credentials, and encrypted traffic that blends into normal activity.

Point-in-time security controls struggle to identify these campaigns because no single event looks overtly malicious. Detection typically requires correlating small, low-confidence signals across endpoints, identity systems, network traffic, cloud services, and logs over extended periods of time.

Without continuous monitoring and active threat hunting, organizations may unknowingly provide attackers with months of unrestricted access.

How Organizations Can Defend Against APTs

Defending against APTs is less about individual point solutions and more about layered visibility, continuous monitoring, and rapid response. Organizations need the ability to detect early-stage intrusion attempts, identify unusual behavior over time, and respond quickly when subtle indicators begin to form a larger pattern.

Strong identity security, hardened endpoints, proper network segmentation, and disciplined patch management all reduce the attack surface. Equally important is having centralized visibility into security telemetry and the operational capability to investigate and respond to threats before they escalate.

Because APT campaigns unfold over time, organizations that rely solely on alert-based security often miss the early signals. Continuous detection and response, paired with threat intelligence and proactive hunting, is essential for surfacing the slow-burn behaviors that define APT activity.

APTs are a Strategic Risk, Not Just a Technical One

Advanced Persistent Threats represent a strategic threat to business operations, intellectual property, and long-term resilience. As attackers become more methodical and patient, organizations must evolve from reactive security models to approaches that assume breach and focus on visibility, detection, and response across the full attack lifecycle.

Understanding how APTs operate is the foundation. Building the capability to identify and stop them before meaningful damage occurs is what separates resilient organizations from those that become case studies.

Learn more about the potential of APT-led attacks in our Threat Research catalogue.

If you are interested in a more holistic, continuous, and wide-reaching approach to security, contact us. We would love to connect with you.