APTs (Advanced Persistent Threats) are sophisticated threat groups, usually financially backed by countries, that perform well-targeted attacks on an organization, nation, or state.

Goals of APTs

The goals of APTs are primarily to

Characteristics of APTs

APT Identification

There are two main factors that can be used to identify if an attack can be attributed to an APT or if it is a random attack:

Technical Identification - APTs often create customized and complex threat vectors, malware, and techniques. These unique signatures and methods can be used as an indicator to identify if the actors behind an attack are an APT.

Context - Attacks by APTs are usually conducted for geopolitical, military, or financial gain. Understanding the context behind an attack can help identify the APT or the sponsor behind it.

Types of APT Groups

i) Nation-State Sponsored Groups

These are APTs that are sponsored, funded, directed, and backed by a government to conduct cyber operations.

Motivation - The intention of such attacks is usually to steal political, military, or economy-related sensitive data, conduct IP theft, and damage the critical infrastructure of an organization, or even influence public opinion on elections.

Targets - Targets for these groups include governments, defense contractors, journalist organizations, energy-related organizations, and more.

ii) Financially Motivated Groups

These APTs target large organizations with custom attacks or zero-day vulnerabilities, often in ransomware attacks.

Motivation - Financial gain. This is usually done through ransomware attacks, stealing users' banking details, credit card data, and more.

Target - Financial institutions, hospitals, and healthcare sectors.

iii) Hacktivist-Backed APTs

These are APTs associated with goals that promote political agendas or ideologies.

APT Naming Conventions

The naming conventions of APT groups are often based on geographic or nation-state associations. The APTs are usually named after animals that represent the country or region to which they belong.

Bears The bear is the national symbol of Russia; therefore, it is associated with Russian APT groups.

Eg*: Cozy Bear (APT29) and Fancy Bear (APT28)*

Pandas The panda is an iconic symbol of China and represents Chinese APT groups.

Eg*: Elderwood Panda*

Falcons These are a symbol of strength and pride in Middle Eastern and North African cultures.

Eg*: Desert Falcon*

Naming Anomalies

Various cybersecurity companies, antivirus vendors, researchers, and attribution organizations like CrowdStrike use different naming conventions based on the country or state of origin.

Therefore, a common reference sheet titled "APT Groups & Operations" has been created, which provides clear-cut, well-structured details of these groups.

https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml?embedable=true