Explaining What an APT is in Cybersecurity

Cybersecurity software companies have a habit of latching on to certain buzzwords or other jargon terms in order to attract new business. You’ve probably heard of SIEM solutions if you work in IT at any medium to large organization. APT is another buzzword that companies like to market their products to defend against, and it’s worth explaining what the term means because this threat often results in an extremely effective and damaging data compromise.

Advanced Persistent Threats Explained

An Advanced Persistent Threat is a mission-oriented attack on a corporate network typically conducted with the aim of stealing proprietary data. This type of data is particularly sensitive and often goes by the term “trade secrets”.

The following steps explain the usual progress of a successful APT attack:

  1. First compromise: A malicious party targets a corporate network, usually via precise social engineering, and establishes a foothold in the network with appropriate technological assistance, such as a Macro or Java applet.
  2. Ensuring future access: The attacker uses his/her own knowledge and skills to establish a customized route into the network without needing to perform the first compromise attack again. This usually involves fooling the target’s IT security team with traffic that looks legitimate.
  3. Privilege escalation: With a foothold into the network, the attacker seeks to gain administrator access to take more control.
  4. Infrastructure scrutiny: With the extra privileges that come from administrative access, the attacker can find out more information about the network, such as key infrastructure and important relationships of trust.
  5. Network expansion: Having established administrative access and conducted extra scrutiny, the attacker expands their control of the network as necessary to get access to the target information.
  6. Achieve target: The successful completion of the mission, obtaining sensitive data belonging to the target organization, is the most critical step in the APT attack and is its raison d’etre.

With an APT, there is always an aim to obtain some kind of information. This threat stands in contrast to say DDoS attacks, in which the aim is often to disrupt an organization’s business continuity. The key tenets of all APTs are stealth, patience, and goal-orientation.

Advanced Persistent Threat Protection

It’s often the case in infosec that learning about the things that don’t protect your systems is as much help in protecting your company as learning about what works. Given the steps above, we can say protection will NOT result from:

  • Malware detection: the point of an APT is that it is advanced, which means that the attacker will rarely if ever use any commonly known malware or backdoor trojan to gain a foothold within a network.
  • Auditing logins: checking logs to notice strange times at which users have logged into systems is not a strategy likely to protect against this type of compromise. The reason is that in step 2, the intruder establishes a customized toolkit that ensures future access without needing to repeat the first compromise.
  • Relying on suspicious IP addresses: some sources say you can find an in-progress APT by monitoring logins to internal email addresses and detecting suspicious IP addresses. A skilled hacker often logs in from inside your network, leaving no trace of suspicion in the IP address.

Closing Thoughts

Advanced persistent threats are extremely effective information security attacks that all companies need to worry about, especially the largest organizations. Hospitals, universities, pharmaceutical companies, large financial corporations, and even government agencies are all viable targets because they all have one thing in common—they store sensitive, valuable information.

1 thought on “Explaining What an APT is in Cybersecurity”

Comments are closed.

Your subscription could not be saved. Please try again.
Your subscription has been successful.

RonanTheWriter Newsletter

Subscribe for recommended business tech solutions, reading resources, and exclusive tips. 

We use Sendinblue as our marketing platform. By Clicking below to submit this form, you acknowledge that the information you provided will be transferred to Sendinblue for processing in accordance with their terms of use