Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

Advanced Persistent Threat (APT)

An Advanced Persistent Threat is a sophisticated, prolonged cyberattack in which an adversary gains unauthorized access to a network and remains undetected for an extended period. APT actors are typically nation-states or highly organized criminal groups targeting high-value organizations. In third-party cyber risk management, APT activity against a vendor represents a significant risk to any organization connected to that vendor's systems or data.

What Makes a Threat Actor Advanced and Persistent?

Black Kite's 2026 Supply Chain Vulnerability Report tracked several state-sponsored groups by reach: APT29 targeted organizations in 49 countries, APT41 in 37, and Volt Typhoon in only 13 countries yet posted the highest overall exposure score in Black Kite's dataset, built on long-term persistence inside critical infrastructure and edge devices. Three traits separate an APT from an opportunistic attacker. It's technically advanced, it stays persistent, and it's deliberately targeted.

Advanced Means Custom-Built, Adaptive Tools

An APT group builds or buys custom malware, chains zero-day vulnerabilities together, and adapts its tooling to each individual target. This is manual, resourced work, closer to a research project than a smash-and-grab.

Persistent Means Staying Undetected for Months

The goal is sustained, ongoing access. Groups cover their tracks by deleting logs, blending into normal traffic, and reestablishing footholds if one is discovered, which is why detection often lags the initial breach by months.

Targeted Means One Organization, Studied in Advance

An APT operator picks a specific target and studies it, mapping the organization's vendors, executives, and systems before the first intrusion attempt. The tactics, techniques, and procedures behind a campaign are documented and tracked, which is how defenders recognize a known group's fingerprint on a new intrusion using the MITRE ATT&CK framework.

How Is an APT Different From a Ransomware Group?

A ransomware group wants a fast payout. An APT wants to stay inside as long as possible, and the two rarely share a playbook.

Ransomware operators favor speed and scale, hitting as many victims as possible before encrypting systems and demanding payment within days. An APT group plays the opposite game: it minimizes noise, avoids anything that would trigger an incident response, and can sit inside a network for months gathering intelligence before ever taking an action the victim would notice. A threat actor is the umbrella term covering both. An APT is the patient subset, built for slow, sustained access over quick, visible wins.

How Do APTs Use Your Vendors to Reach You?

Compromising one shared vendor gives an APT group a foothold into every downstream organization that trusts that vendor's access. A single foundational tool, once compromised, can open a path into thousands of otherwise well-defended targets, because the victim's own defenses never see the intrusion coming through a trusted connection. It's far cheaper to compromise one widely used vendor than to breach every one of its customers directly, which is the same logic behind nation-state software supply chain campaigns.

Geopolitical context sharpens the picture further. State-sponsored groups tend to follow their sponsor's strategic interests, which means a vendor's industry, headquarters location, and customer base all factor into whether it sits in an APT group's crosshairs, alongside its patch level.

Can You Tell Which of Your Vendors an APT Group Is Targeting?

Attribution is genuinely hard, and no single external signal proves a specific group is inside a specific network. What's observable from the outside is whether a vendor carries the exposure indicators known APT groups exploit. Any single indicator, alone, is a weak signal. Together, they show which vendors match the pattern closely enough to warrant a closer look before an incident happens.

The Exposure Indicators That Match an APT's Pattern

Open remote desktop ports, unpatched CVEs tied to a group's documented TTPs, or credentials already circulating in stealer logs are the observable signals to watch. Black Kite's research found 3.8 billion stolen credentials circulating across the surface, deep, and dark web.

How the Adversary Susceptibility Index Maps Exposure to Named Groups

Black Kite's Adversary Susceptibility Index (ASI™) maps those indicators to specific known groups, including Volt Typhoon, Black Basta, and APT29, so a risk team can filter its vendor ecosystem by susceptibility to a named actor and tailor the view vendor by vendor. It builds on the Ransomware Susceptibility Index®, using RSI as one input alongside CVEs, stealer logs, leaked credentials, and each actor's documented targeting and TTPs.

Adversary Susceptibility Index data also surfaces which region and sector a given actor tends to target, which matters because state-sponsored groups largely follow their sponsor's strategic interests as much as opportunity. FocusTags® flag vendors potentially exposed to a high-profile cyber event, such as an actively exploited vulnerability, and geopolitical risk monitoring shows which vendors have operations or digital assets in regions affected by conflict, sanctions, or instability.

What Susceptibility Scoring Can and Can't Confirm

An indicator of compromise is evidence that an intrusion may already have happened, while susceptibility scoring exists to flag the risk earlier, before that point. Both are covered alongside dozens of related concepts in Black Kite's TPRM and TPCRM glossary, including how risk intelligence differs from threat intelligence in practice. This kind of signal narrows a near-infinite vendor list down to the ones worth checking first. It is a prioritization tool, and confirming that an APT is actually inside a given vendor's network today still takes the vendor's own internal detection.

Black Kite's Cyber Villains and Threat Actors Dossier profiles major ransomware groups, covering their motives and calling cards.

See also: Top Threat Actor Trends