Back to glossaryCyber

APT (Advanced Persistent Threat)

A malicious actor, often state-sponsored, conducting targeted and prolonged intrusions into a network while seeking to remain undetected.

Definition

An APT (Advanced Persistent Threat) refers to a threat actor with significant resources, usually a state or a state-sponsored group, that conducts targeted, persistent and highly sophisticated intrusion campaigns against specific organizations for purposes of espionage, sabotage or strategic pre-positioning. The term highlights three fundamental characteristics. The advanced aspect refers to the use of sophisticated attack techniques, novel exploits (zero-days) and custom-built tools. The persistent aspect means the attacker seeks to maintain discreet long-term access, sometimes for months or years, blending into legitimate traffic. The threat aspect underscores intentionality and precise targeting. APT groups are often designated by names or numbers, such as Lazarus (North Korea), Sandworm (Russia, GRU), APT28 or Fancy Bear (Russia, FSB), and APT41 (China). Their dwell time, the duration between initial intrusion and detection, is often measured in hundreds of days. For cyber insurance, APTs raise several specific issues: a war or sovereign act exclusion may apply, dating the initial compromise is complex, and the distinction between espionage and sabotage conditions the triggering of cover.

Example

The 2020 SolarWinds attack, attributed to APT29 (Cozy Bear) linked to Russian SVR, compromised the Orion IT management platform for months. Thousands of organizations, including US government agencies, downloaded a malicious update without detection, illustrating a dwell time of several months.

Related terms
Related articles
Also known as

APT, Advanced Persistent Threat, menace persistante avancée, attaquant étatique