APT Malware
Introduction
Section titled “Introduction”APT (Advanced Persistent Threat) malware refers to custom-developed tooling used by nation-state actors for long-term espionage, intellectual property theft, strategic intelligence, and sabotage. APT groups are well-resourced, patient, and operate with specific strategic objectives.
APT Characteristics
Section titled “APT Characteristics”| Attribute | Description |
|---|---|
| Attribution | Nation-state (intelligence, military) |
| Objectives | Espionage, IP theft, sabotage, influence |
| Timeline | Months to years (dwell time 200+ days avg) |
| Tooling | Custom, modular, zero-days, supply chain |
| OPSEC | High; anti-forensics, living-off-the-land |
| Infrastructure | Dedicated, often compromised hosts |
Notable APT Groups
Section titled “Notable APT Groups”| Group | Attribution | Notable Tools |
|---|---|---|
| APT1 / Comment Crew | China (PLA Unit 61398) | Custom backdoors |
| APT10 / Stone Panda | China (MSS) | PlugX, RedLeaves |
| APT28 / Fancy Bear | Russia (GRU) | X-Agent, X-Tunnel |
| APT29 / Cozy Bear | Russia (SVR) | WellMess, GoldMax |
| Lazarus Group | North Korea | WannaCry, Swift attacks |
| Equation Group | USA (NSA) | EQUATIONDRUG, GrayFish |
| Turla | Russia (FSB) | Carbon, Snake |
| APT41 / Winnti | China | Supply chain, Winnti |
| Sandworm | Russia (GRU) | NotPetya, Industroyer |
APT Malware Characteristics
Section titled “APT Malware Characteristics”| Trait | Description |
|---|---|
| Custom development | Not commodity; built for specific ops |
| Modular architecture | Plugins for specific tasks |
| Zero-day usage | Unpatched vulns for initial access |
| Living-off-the-land | Built-in tools (PowerShell, WMI, certutil) |
| Anti-forensics | Timestomping, log clearing, encryption |
| Long dwell time | Months to years undetected |
| Multi-stage | Loader → implant → modules |
Notable Malware Families
Section titled “Notable Malware Families”| Family | Attribution | Notable |
|---|---|---|
| PlugX / Korplug | APT10, APT41 | Modular RAT |
| RedLeaves | APT10 | PlugX variant |
| X-Agent / CHOPSTICK | APT28 | Cross-platform RAT |
| WellMess / GoldMax | APT29 | Supply chain (SolarWinds) |
| Sunburst / SUNSPOT | APT29 | SolarWinds supply chain |
| Industroyer / Crashoverride | Sandworm | ICS targeting |
| NotPetya | Sandworm | Wiper disguised as ransomware |
| Olympic Destroyer | Sandworm | 2018 Olympics sabotage |
APT Lifecycle
Section titled “APT Lifecycle”1. RECONNAISSANCE └─ OSINT, spear-phishing prep, infrastructure
2. INITIAL ACCESS └─ Spear-phish, exploit, supply chain, watering hole
3. EXECUTION & PERSISTENCE └─ Custom loader → implant → scheduled tasks, WMI
4. PRIVILEGE ESCALATION └─ Zero-day, kernel exploit, token manipulation
5. CREDENTIAL ACCESS └─ LSASS dump, DCSync, Kerberoasting
6. DISCOVERY & LATERAL MOVEMENT └─ AD enumeration, SMB/WMI/PSExec, pass-the-hash
7. COLLECTION & EXFILTRATION └─ Staging, encryption, C2 exfil (DNS, HTTPS, cloud)
8. CLEANUP / PERSISTENCE └─ Anti-forensics, backup implants, scheduled returnDefence
Section titled “Defence”- ✅ Zero Trust — Assume breach; verify every access
- ✅ EDR + NDR — Behavioural detection, not signatures
- ✅ Threat Intelligence — APT TTPs, IOCs, attributions
- ✅ Hunt Team — Proactive threat hunting
- ✅ Supply Chain Security — SBOM, reproducible builds
- ✅ Identity Protection — FIDO2, tiered admin, PAM
- ✅ Network Segmentation — Limit lateral movement
- ✅ Incident Response — APT-specific playbooks
MITRE ATT&CK
Section titled “MITRE ATT&CK”APT malware spans all 14 ATT&CK tactics. Key techniques:
- Initial Access: T1190, T1195, T1199
- Persistence: T1505, T1547, T1053
- Privilege Escalation: T1068, T1055, T1078
- Credential Access: T1003, T1558, T1003.001
- Lateral Movement: T1021, T1550, T1563
- Exfiltration: T1041, T1048, T1567
Related
Section titled “Related”- Supply-Chain Malware — SolarWinds, XZ Utils
- Supply Chain — Broader topic
- OT/ICS Malware — ICS-targeting APTs