APT
An Advanced Persistent Threat (APT) is an attacker group with significant time, money, and clear objectives.
An Advanced Persistent Threat (APT) is an attacker group with significant time, money, and clear objectives. These attacks are often state-sponsored and can last for several months.
How it works
APT groups carefully select their targets. These include government agencies, defence contractors, research facilities, or financial institutions. Initial access is often gained through spear phishing, vulnerabilities in perimeter systems such as VPNs, or through suppliers. Afterwards, attackers move cautiously within the network. They use legitimate tools and avoid conspicuous actions. The primary goal is usually espionage, not quick financial gain.
For example, a group exploits a firewall vulnerability before a patch is available. They create a hidden account and wait for several weeks. Afterwards, they exfiltrate data from email inboxes in small amounts during office hours. The attack is only detected when an analyst finds unusual access to the mail interface during threat hunting.
What to look out for
- Perimeter systems like VPNs, firewalls, and mail gateways are common entry points. Patch them promptly and monitor their logs.
- Watch for subtle signals: new accounts, new forwarding rules, or access at unusual times.
- Retain logs for a sufficient period. APT attacks are often discovered months later.
- Assess if your organisation is a realistic target. This will determine the necessary level of effort.
Switzerland and regulation
The National Cyber Security Centre (NCSC) and the Federal Intelligence Service regularly warn of state actors attacking Swiss organisations. Affected targets mainly include government bodies, international organisations, industry, and research. Since 1 April 2025, operators of critical infrastructure must report cyberattacks meeting the criteria of the Information Security Act (ISG) to the NCSC within 24 hours of discovery.
Typical mistakes
Many organisations believe they are too small to be targeted by APT groups. However, suppliers of larger targets are often the initial point of entry. A second mistake is looking only for malware. APT groups frequently operate without malware and use native system tools instead.
How we implement it
We combine behavioural detection with threat hunting and threat intelligence.