Advanced persistent threat (APT)
In threat intelligence, an advanced persistent threat is a well-resourced attacker that targets a specific entity and maintains access over long periods to meet an objective. The defining words are targeted and persistent: the adversary chose you, and is prepared to stay, which changes what defence has to achieve.
What it is
An advanced persistent threat (APT) is a sustained campaign directed at specific systems, not a one-off attack. Whoever runs it wants to get in, stay without being detected, and take information out or keep watch over long periods.
Three traits set it apart. It is targeted: the victim was chosen, not happened upon. It is persistent: access is held over time rather than spent in a single hit. And it is well resourced: bespoke tooling and evasion techniques that do not appear in an opportunistic attack.
It usually follows a recognisable path: target selection, entry, establishing persistence, lateral movement and data exfiltration.
How it works
The distinction is one of intent and resources, not of tooling. A commodity operator scans the internet, takes what falls out, and moves on when a target resists. A persistent actor selects the target first, then spends time understanding it: the suppliers, the technologies, the people, the schedules. Objectives are usually intelligence, intellectual property or positioning for later disruption, so the operation is measured in months and quiet access is worth more than immediate gain.
What follows from that is patience as a technique. Slow reconnaissance, a small number of credentials used carefully, several independent means of return, and activity timed to blend with normal working patterns.
What goes wrong
The word advanced misleads people into expecting exotic tooling, and the entry is normally not exotic at all: a phishing message aimed at four people, a supplier with a trusted network route, an unpatched appliance at the edge, or credentials bought from a broker. The sophistication appears afterwards, in tradecraft, in how the operator handles credentials and how carefully they avoid making noise.
The practical consequence is that prevention-shaped defence is the wrong bet against this class. An adversary who will try for six months will eventually find a route, so the question that matters is how quickly the movement afterwards is noticed, which is a detection and response question. That is why assumed breach is the sensible starting posture for an exercise against this profile.
The second failure is intelligence consumed as names rather than as behaviour. Loading a group’s published indicators gives you their infrastructure from a previous operation. Reading the techniques and mapping them to ATT&CK gives you something that still applies after the operator changes servers.
Where this shows up in an audit
An engagement against this profile is adversary emulation: we select an actor whose interests plausibly include the client’s sector, take their documented techniques, and run those rather than our own favourites. The value is that the resulting coverage report is about a real adversary’s behaviour instead of a generic checklist. The deliverable is the timeline of our activity against what the defenders saw, and the honest measure is time to detection, not whether we got in. This is part of how an adversary exercise reproduces a targeted attacker.