News

APT Groups and Nation-State Threat Actors: How to Track TTPs, Attribution, and Campaign Intelligence

APT groups use tailored malware and long dwell times. How defenders track TTPs, attribute campaigns, and build proactive intelligence in 2026.
Sami Malik
Copywriter

In November 2023, Microsoft published a detailed report on a threat actor it tracks as Midnight Blizzard, a group attributed to the Russian Foreign Intelligence Service (SVR). The report documented how the group had spent months targeting cloud service providers, conducting patient reconnaissance before moving to credential theft and lateral movement. What made the intelligence valuable was not the individual indicators, which would be replaced quickly, but the documented tactics: the specific spear-phishing techniques, the cloud service abuse patterns, and the tradecraft that the group applies consistently across campaigns. This TTP-level intelligence is what distinguishes APT tracking from simple IOC collection.

Advanced Persistent Threat groups, the term coined to describe nation-state-sponsored or nation-state-aligned threat actors operating with advanced capabilities and long-term objectives, present a different intelligence challenge from cybercriminal groups. Where criminal operators are motivated primarily by financial return and operate under the constraints of market economics, APT groups operate with state resources, patient timelines, and objectives that include espionage, intellectual property theft, and in some cases pre-positioning for destructive attacks. Understanding how APT groups differ from cybercriminal operators is the starting point for building an effective APT intelligence programme.

How APT Groups Are Identified and Tracked

APT group tracking relies on clustering observed activity into groups based on shared characteristics: common malware families, overlapping infrastructure, similar targeting patterns, and consistent tactical choices. This clustering is done independently by multiple organisations, which is why the same group often carries different names: the group Microsoft calls Midnight Blizzard is called APT29 by Mandiant, Cozy Bear by CrowdStrike, and The Dukes by ESET. The MITRE ATT&CK Groups database provides a cross-reference of group aliases that helps analysts navigate this naming fragmentation.

Attribution, connecting observed activity to a specific nation-state actor, is analytically distinct from tracking and carries a higher evidentiary burden. Technical indicators can support attribution but rarely provide definitive proof alone. Code-language artefacts, working hours that correspond to specific time zones, targeting patterns consistent with a nation-state's geopolitical interests, and infrastructure overlaps with previously attributed operations all contribute to attribution assessments. The confidence level of an attribution should always be stated explicitly, as attribution errors have significant consequences for both diplomatic relationships and defensive priorities.

For most organisations, the operationally relevant question is not which specific nation-state is responsible for observed activity but rather: which APT groups are known to target our sector, what TTPs do they use, and what controls would detect or prevent those TTPs? This TTP-focused approach to APT intelligence is both more actionable and less dependent on the high-confidence attribution that only governments and major intelligence organisations can achieve with consistency.

Living-Off-the-Land: How APTs Evade Detection

One of the defining characteristics of sophisticated APT operations is the extensive use of living-off-the-land (LOTL) techniques: using legitimate operating system tools and features for malicious purposes rather than deploying custom malware that security tools might detect. PowerShell, WMI (Windows Management Instrumentation), PsExec, and other legitimate administrative tools are used for lateral movement, credential harvesting, and data staging in APT operations precisely because their use blends with legitimate administrative activity in environments where these tools are regularly used.

The CISA advisory on Volt Typhoon, a Chinese APT group, published in May 2023, documented extensive LOTL technique use: the group used built-in network administration tools to blend its reconnaissance traffic with normal network activity, making detection dependent on behavioural analysis rather than signature-based detection. The advisory specifically noted that Volt Typhoon avoided malware that would trigger endpoint security tools, relying instead on tools already present on compromised systems.

For defenders, the implication is that APT detection cannot rely on signature-based detection alone. Behavioural detection, identifying anomalous use of legitimate tools based on context and sequence, is the required approach. This is technically more demanding than signature matching but more effective against sophisticated actors who invest in understanding and evading known signatures before deploying their techniques.

APT Targeting Patterns and Sector Intelligence

APT groups are not indiscriminate in their targeting. Each group has priorities that reflect the intelligence collection or strategic objectives of its sponsoring state. Chinese APT groups historically have targeted defence contractors, technology companies, and research institutions with intellectual property of strategic value to Chinese industrial and military programmes. Russian APT groups have focused on government targets, think tanks, and energy infrastructure in NATO member states. North Korean groups have combined espionage objectives with financially motivated attacks on cryptocurrency platforms to generate revenue for the state.

Understanding which APT groups are known to target your organisation's sector is the starting point for a prioritised APT intelligence programme. If your organisation operates in a sector that is a known target for specific APT groups, the intelligence priority should be understanding those groups' TTPs in sufficient detail to assess whether your current controls would detect or prevent their techniques. The MITRE ATT&CK framework's group pages document the specific techniques associated with each known APT group, providing a starting point for this assessment.

Sector-specific intelligence sharing organisations, including Information Sharing and Analysis Centres (ISACs) in sectors including financial services, healthcare, and energy, provide access to threat intelligence that is specifically relevant to each sector's threat landscape. Participation in these sharing communities gives organisations access to intelligence that individual organisations could not develop independently, including early warning of APT campaigns targeting their sector before those campaigns become publicly known.

Dwell Time and the Long-Horizon Threat

APT operations are characterised by long dwell times, the period between initial compromise and either detection by the defender or completion of the attacker's objective. Where commodity cybercriminal attacks typically move quickly from initial access to execution of their objective, APT groups invest time in patient reconnaissance, establishing persistent access through multiple mechanisms, and positioning for their ultimate objective before taking actions that might trigger detection.

The Mandiant M-Trends report has tracked global median dwell times over multiple years, showing a general trend of improvement but with significant variation by region and detection method. Organisations that detect intrusions through external notification, meaning a third party informed them of a compromise, consistently show longer dwell times than organisations that detect intrusions through internal means. This underscores the value of external intelligence sources, including dark web monitoring and threat intelligence feeds, that can surface evidence of APT activity before internal detection tools identify it.

Building an APT Intelligence Programme

An effective APT intelligence programme begins with defining the threat actors most likely to target the organisation based on its sector, geopolitical exposure, and technology profile. This threat actor prioritisation drives collection priorities: which APT groups' activities should be monitored most closely, what TTPs should be used to inform detection engineering, and which intelligence sources are most likely to provide early warning of targeting activity.

Technical intelligence collection for APT tracking includes monitoring for infrastructure associated with known APT groups: domains using registrar and hosting patterns consistent with known APT infrastructure, TLS certificates with characteristic fields, and IP addresses appearing in threat intelligence feeds as APT-associated. This infrastructure monitoring can surface new APT campaign activity before attacks are launched against specific targets, providing defenders with the lead time needed to validate controls and prepare response plans.

The integration of APT intelligence with internal security operations requires translating group-level TTP intelligence into specific detection rules and hunting queries. If a monitored APT group is known to use a specific persistence mechanism or credential harvesting technique, the detection engineering team should verify that existing detection logic would identify that technique if observed in the environment, and develop additional rules if gaps are identified.

The Limits of Open-Source APT Intelligence

The public reporting on APT groups published by security vendors, government agencies, and research teams provides a foundation for APT intelligence, but it comes with important limitations that practitioners must account for. Public reports reflect what vendors have investigated and chosen to disclose, which is influenced by commercial considerations, disclosure timing relative to ongoing investigations, and the need to protect sensitive sources and methods. The most sophisticated and active APT campaigns may be the least represented in public reporting precisely because they have not been detected or because their discovery has not yet been disclosed.

Attribution in public reports also carries limitations. Vendors make attribution calls based on their own analytical standards and their available intelligence, and these calls may be contested by other organisations with access to different data. For defenders, the appropriate response to conflicting attribution claims is to focus on the TTPs that are documented and actionable, regardless of which specific nation-state is assessed as responsible. Controls that detect the documented techniques remain effective whether the attribution is accurate or not.

The time lag between APT campaign activity and public reporting means that practitioners who rely solely on public reports are always working with historical intelligence. A report published today about a campaign observed six months ago provides useful context but does not address what the same group is doing right now. Supplementing public reporting with real-time intelligence sources, including threat intelligence platform feeds, sector-specific ISAC information, and dark web monitoring for indicators of targeting activity, reduces this time lag and provides a more current picture of the threat landscape.

Defendis integrates APT campaign intelligence with real-time monitoring of infrastructure associated with known threat actor groups, providing organisations with both the historical context from public reporting and early warning signals that precede public disclosure of new campaigns.

Tracking APT Infrastructure: A Practitioner's Approach

APT groups do not operate with unlimited resources. Their infrastructure must balance operational security requirements, cost considerations, and the practical needs of running persistent operations against multiple targets simultaneously. These constraints create observable patterns that experienced threat intelligence analysts can use to track APT infrastructure across time and geographic locations, even as individual components are rotated or retired.

Infrastructure clustering is one of the most productive analytical techniques for APT tracking. When a new domain or IP is identified as APT infrastructure through malware analysis or incident response, passive DNS lookups can reveal other domains that have resolved to the same IP address, other IPs that the same domain has resolved to, and the timing patterns of these associations. These clusters often reveal infrastructure that was not previously associated with the APT group, extending the known indicator set. Certificate data provides additional clustering opportunities: APT groups often use certificates with distinctive parameters (specific subject fields, unusual validity periods, or self-signed certificates with distinctive properties) that link infrastructure components that have no DNS or IP overlap.

The geographic and hosting provider patterns of APT infrastructure are also informative. Nation-state actors affiliated with specific governments often use hosting providers in specific jurisdictions, either for operational security reasons or because those providers are less likely to respond to abuse reports from Western organisations. Tracking these hosting provider preferences creates predictive intelligence: when a new campaign is observed using infrastructure at the same hosting provider as previously attributed campaigns, this geographic context is one factor in the attribution analysis. Combining infrastructure clustering with TTP analysis and the campaign timeline creates the multi-layered evidence base that supports confident attribution, which is the foundation for appropriate strategic response decisions when an APT intrusion is detected.

Frequently Asked Questions

How are APT groups named and who names them?

APT group naming is fragmented across the security industry, with different vendors using different naming conventions and often applying different names to the same groups. Mandiant uses APT numbers (APT28, APT29), CrowdStrike uses animal-country composites (Fancy Bear, Cozy Bear), Microsoft uses weather-related names (Midnight Blizzard), and various national agencies use their own systems. This multiplicity of names for the same groups creates confusion when correlating intelligence from different sources. Services like MITRE ATT&CK maintain tables that map between the naming conventions of major vendors, providing a translation layer for analysts working with multiple intelligence sources.

What distinguishes an APT from a sophisticated criminal group?

The primary distinctions are motivation, dwell time, and operational discipline. APT groups are typically motivated by espionage, geopolitical objectives, or long-term strategic goals rather than immediate financial gain. They invest in maintaining persistent, undetected access over months or years, which requires sophisticated operational security that limits their behaviour in ways that purely financially motivated actors do not need to observe. Criminal groups prioritise speed to monetisation over persistence; APTs prioritise access longevity over speed. In practice, the boundary has become blurrier as some nation-states use criminal infrastructure for plausible deniability and some criminal groups demonstrate APT-level sophistication.

Should every organisation worry about APT groups?

The relevance of APT threat intelligence depends on the organisation's sector and what information or access it holds that would be valuable to nation-state actors. Government contractors, defence suppliers, advanced technology companies, critical infrastructure operators, and financial market participants are the most consistent APT targets. For organisations in these sectors, APT threat intelligence is directly relevant to their defensive posture. Organisations in less strategically sensitive sectors are more likely to encounter opportunistic criminal threats than targeted APT activity, though they may still be affected as collateral damage in supply chain attacks targeting more sensitive entities in their ecosystems.

How do organisations detect APT intrusions that have maintained dwell time for months?

APT detection after extended dwell time typically requires threat hunting: proactive investigation based on intelligence about APT TTPs rather than waiting for automated alerts. Threat hunters look for anomalies that standard detection rules do not flag because they fall within individually permissible parameters: unusual authentication patterns aggregated over time, data staging activity that is slow enough to avoid volume-based alerts, and living-off-the-land techniques using legitimate tools in unusual combinations. Intelligence about the specific TTPs of APT groups known to target the organisation's sector enables threat hunters to focus their investigations on the most likely indicators, making the effort tractable despite the large volume of logs that must be searched.

Integrating APT Intelligence into Security Operations

APT intelligence is most valuable when it is operationalised into specific detection hypotheses and hunting campaigns, rather than remaining in strategic reports that inform posture decisions without changing detection capabilities. The gap between receiving intelligence about a specific APT group's TTPs and having detections in place that would alert if those TTPs were observed in the environment is the gap that determines whether APT intelligence produces security outcomes or simply security awareness.

The operationalisation process starts with mapping APT TTPs documented in intelligence reports to the MITRE ATT&CK framework, which provides a common language for describing adversary behaviour in terms that security tools can implement. Once an APT group's TTPs are mapped to ATT&CK techniques, security teams can assess their existing detection coverage against each technique and identify gaps where they have no detection capability. These gaps are the prioritised targets for detection engineering investment: building SIEM rules, EDR policies, and network monitoring capabilities that would alert if the specific techniques associated with the most relevant APT groups were observed.

Threat hunting, the proactive search for evidence of APT activity that has not triggered automated alerts, is the operational intelligence activity that addresses the detection gap most directly. A threat hunting team that uses APT TTP intelligence to design hypotheses, "If APT group X were in our environment, what evidence would we expect to find in our logs?" can systematically search for evidence of intrusion that evaded automated detection. Regular threat hunting cycles, calibrated to the APT groups most relevant to the organisation's sector and risk profile, are one of the most effective applications of APT intelligence in a mature security programme. Defendis provides the APT infrastructure monitoring that detects when threat actor infrastructure begins targeting your sector, enabling threat hunting campaigns timed to specific threat actor activity rather than on a fixed calendar schedule.

Building a Sector-Specific APT Watchlist

Not every APT group is equally relevant to every organisation. Building a watchlist of APT groups that have historically targeted organisations in your sector, your region, and with your technology profile focuses analytical resources on the threats most likely to be operationally relevant. Public resources including MITRE ATT&CK Groups, CISA advisories, and vendor annual threat reports provide starting data for this watchlist. Updating it quarterly as new attributions and targeting patterns are documented keeps the watchlist current.

A sector-specific APT watchlist enables more targeted threat hunting and detection engineering: instead of attempting to detect activity patterns for dozens of APT groups, the security team focuses its detection investment on the techniques associated with the groups most likely to target the organisation. This focus produces better detection quality for the threats that matter most, rather than thin coverage across the full range of APT activity. Defendis provides targeted intelligence on APT groups active in your sector, updating your watchlist with current campaign activity and newly attributed infrastructure.

How Defendis Tracks APT Infrastructure and Vulnerability Exposure for Your Organisation

APT campaign infrastructure leaves detectable traces: newly registered domains matching known attacker patterns, TLS certificates with characteristic fields, and C2 servers reusing known bulletproof hosting. Defendis monitors these signals alongside CISA KEV updates and exploit availability data to surface intelligence that connects external threats to your specific technology stack and exposure profile. When a KEV entry affects software you run, or when APT infrastructure targets your sector, Defendis delivers a prioritised alert before the threat reaches your environment.

Request a demo to see how Defendis maps APT intelligence and vulnerability exposure to your organisation's specific risk profile.

About the author
Sami Malik is a copywriter passionate about crafting clear, engaging, and impactful content that helps brands connect with their audience through storytelling and strategy.

Related Articles

Discover simplified
Cyber Risk Management
Learn how to prevent cyberattacks proactively with a free trial of Defendis.