# What is an Advanced Persistent Threat (APT)?

> An advanced persistent threat (APT) is a capable, well-resourced adversary — or, in common industry usage, its sustained campaign — that pursues strategic objectives over an extended period, uses multiple attack paths, adapts to resistance, and seeks to establish or renew access.

- Canonical URL: https://yellowcube.eu/glossary/advanced-persistent-threat/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The label does not mean every targeted intrusion, state-sponsored actor, espionage case, or technically complex malware event is an APT.

Objectives can include intelligence collection, disruption, influence, theft, or positioning for later action. APTs may use custom capabilities or ordinary methods such as stolen credentials, public tools, social engineering, and administration features. Names vary between researchers, so attribution requires evidence.

### Key points

- **Distinguishing characteristics:** Consider resources, expertise, persistence of objectives, repeated access efforts, operational security, adaptation, and the ability to combine cyber, physical, human, or supply-chain paths.
- **Defensive evidence:** Preserve timelines and relate identity, endpoint, network, cloud, application, and external intelligence to tactics, techniques, and procedures (TTPs) rather than one indicator or malware family.
- **Risk response:** Prioritize important missions and data, reduce exposed paths and standing privilege, segment critical functions, monitor durable behaviors, rehearse recovery, and plan for attempted re-entry.
- **Important limitation:** “Advanced” is not a measured grade, “persistent” does not prove continuous presence, and an APT label does not establish who directed an operation. Overuse can exaggerate weak evidence, glamorize an actor, and distract from correctable control failures.

### Related terms

[Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Cyber espionage](<https://yellowcube.eu/glossary/cyber-espionage/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Threat actor](<https://yellowcube.eu/glossary/threat-actor/>)

### Sources

[NIST Glossary: Advanced Persistent Threat](https://csrc.nist.gov/glossary/term/advanced_persistent_threat) · [NIST SP 800-172 Rev. 3: Enhanced Security Requirements for Protecting Controlled Unclassified Information](https://csrc.nist.gov/pubs/sp/800/172/r3/final) · [ENISA Glossary: Advanced Persistent Threat](https://www.enisa.europa.eu/media/media-press-kits/enisa-glossary)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

