Skip to content

APT Malware

Risk Level

APT (Advanced Persistent Threat) malware refers to custom-developed tooling used by nation-state actors for long-term espionage, intellectual property theft, strategic intelligence, and sabotage. APT groups are well-resourced, patient, and operate with specific strategic objectives.

AttributeDescription
AttributionNation-state (intelligence, military)
ObjectivesEspionage, IP theft, sabotage, influence
TimelineMonths to years (dwell time 200+ days avg)
ToolingCustom, modular, zero-days, supply chain
OPSECHigh; anti-forensics, living-off-the-land
InfrastructureDedicated, often compromised hosts
GroupAttributionNotable Tools
APT1 / Comment CrewChina (PLA Unit 61398)Custom backdoors
APT10 / Stone PandaChina (MSS)PlugX, RedLeaves
APT28 / Fancy BearRussia (GRU)X-Agent, X-Tunnel
APT29 / Cozy BearRussia (SVR)WellMess, GoldMax
Lazarus GroupNorth KoreaWannaCry, Swift attacks
Equation GroupUSA (NSA)EQUATIONDRUG, GrayFish
TurlaRussia (FSB)Carbon, Snake
APT41 / WinntiChinaSupply chain, Winnti
SandwormRussia (GRU)NotPetya, Industroyer
TraitDescription
Custom developmentNot commodity; built for specific ops
Modular architecturePlugins for specific tasks
Zero-day usageUnpatched vulns for initial access
Living-off-the-landBuilt-in tools (PowerShell, WMI, certutil)
Anti-forensicsTimestomping, log clearing, encryption
Long dwell timeMonths to years undetected
Multi-stageLoader → implant → modules
FamilyAttributionNotable
PlugX / KorplugAPT10, APT41Modular RAT
RedLeavesAPT10PlugX variant
X-Agent / CHOPSTICKAPT28Cross-platform RAT
WellMess / GoldMaxAPT29Supply chain (SolarWinds)
Sunburst / SUNSPOTAPT29SolarWinds supply chain
Industroyer / CrashoverrideSandwormICS targeting
NotPetyaSandwormWiper disguised as ransomware
Olympic DestroyerSandworm2018 Olympics sabotage
1. RECONNAISSANCE
└─ OSINT, spear-phishing prep, infrastructure
2. INITIAL ACCESS
└─ Spear-phish, exploit, supply chain, watering hole
3. EXECUTION & PERSISTENCE
└─ Custom loader → implant → scheduled tasks, WMI
4. PRIVILEGE ESCALATION
└─ Zero-day, kernel exploit, token manipulation
5. CREDENTIAL ACCESS
└─ LSASS dump, DCSync, Kerberoasting
6. DISCOVERY & LATERAL MOVEMENT
└─ AD enumeration, SMB/WMI/PSExec, pass-the-hash
7. COLLECTION & EXFILTRATION
└─ Staging, encryption, C2 exfil (DNS, HTTPS, cloud)
8. CLEANUP / PERSISTENCE
└─ Anti-forensics, backup implants, scheduled return
  • Zero Trust — Assume breach; verify every access
  • EDR + NDR — Behavioural detection, not signatures
  • Threat Intelligence — APT TTPs, IOCs, attributions
  • Hunt Team — Proactive threat hunting
  • Supply Chain Security — SBOM, reproducible builds
  • Identity Protection — FIDO2, tiered admin, PAM
  • Network Segmentation — Limit lateral movement
  • Incident Response — APT-specific playbooks

APT malware spans all 14 ATT&CK tactics. Key techniques:

  • Initial Access: T1190, T1195, T1199
  • Persistence: T1505, T1547, T1053
  • Privilege Escalation: T1068, T1055, T1078
  • Credential Access: T1003, T1558, T1003.001
  • Lateral Movement: T1021, T1550, T1563
  • Exfiltration: T1041, T1048, T1567