
Advanced Persistent Threats, or APTs, are usually tied to state interests, meaning their operations often reflect the goals of a government, military intelligence service, or aligned proxy group. A country-wise view makes the threat easier to understand because the sponsor, tactics, and target patterns often repeat across campaigns.
Understanding the Threat

APT groups are not random hackers working alone. They are typically long-running, highly organized threat actors that use stealth, persistence, and patience to achieve strategic goals such as espionage, intellectual property theft, disruption, or financial gain. In many cases, their activity is linked to countries including China, Russia, North Korea, and Iran.
This blog gives readers a practical map of major APT groups, their country sponsors, and the attacks or exploits they are known for. It is written for security teams, business leaders, students, and general readers who want a clear picture of today’s nation-state cyber threat landscape.
What makes APTs dangerous
APTs are dangerous because they are patient and targeted. Instead of blasting out broad attacks, they often study victims, exploit weak points, and stay hidden for long periods to collect information or maintain access.
They also adapt quickly. Recent reporting shows groups like APT28 weaponizing a Microsoft Office zero-day within a day of disclosure, while APT41 has used web shells, cloud services, and stolen certificates to hide activity and exfiltrate data.

State-sponsored APT list
| APT group | State sponsor | Common targets | Attacks or exploits |
|---|---|---|---|
| APT41 | China | Government, shipping, logistics, media, tech, automotive | Used ANTSWORD and BLUEBEAM web shells, DUSTPAN and DUSTTRAP malware, and cloud services like OneDrive for exfiltration. |
| APT28 | Russia | Ukraine, EU institutions, government agencies | Exploited Microsoft Office CVE-2026-21509, used malicious documents, WebDAV, and Covenant backdoors. |
| Lazarus Group | North Korea | Finance, crypto, government, tech | North Korea state-sponsored actors have used malware such as BLINDINGCAN and other cybercrime-linked tools. |
| APT42 | Iran | Journalists, activists, political targets, cloud accounts | Used enhanced social engineering, phishing, and cloud account compromise. |
| Sandworm | Russia | Critical infrastructure, government, energy | Commonly associated with destructive operations and disruptive campaigns. |
| Kimsuky | North Korea | Think tanks, academics, policy and government users | Known for intelligence collection, phishing, and credential theft. |
| Mustang Panda | China | Government and strategic sectors | Known for espionage-focused campaigns and persistence-heavy operations. |
| APT29 | Russia | Diplomacy, government, research | Associated with stealthy espionage and cloud-oriented intrusion patterns. |
| APT33 | Iran | Aerospace, energy, government-linked interests | Linked to long-running Iranian cyber espionage activity. |
| APT35 | Iran | Political, academic, and media targets | Often associated with credential theft and social engineering. |
China-linked APTs
China-linked groups are often associated with espionage, data theft, and strategic intelligence collection. APT41 is one of the best-known examples because it mixes state-sponsored espionage with financially motivated activity, which makes it unusually broad in scope.
Mandiant reported that APT41 compromised organizations in shipping, logistics, media, entertainment, technology, and automotive sectors, and used ANTSWORD, BLUEBEAM, DUSTPAN, DUSTTRAP, SQLULDR2, and PINEGROVE in the intrusion chain. It also used legitimate cloud tools and stolen certificates to make traffic look normal and to move data out quietly.
Another common China-linked pattern is long-term persistence. These groups often seek access to government networks, telecom systems, intellectual property repositories, and global service providers so they can gather intelligence over time rather than destroy systems immediately.
Russia-linked APTs
Russia-linked APTs are frequently tied to espionage, influence operations, and destructive or disruptive cyber activity. APT28 is a clear example, with recent reporting showing the group exploiting Microsoft Office CVE-2026-21509 against Ukrainian government agencies and EU institutions almost immediately after disclosure.
The campaign used malicious documents, WebDAV, COM hijacking, scheduled tasks, and the Covenant framework as part of a complex infection chain. That speed matters because it shows defenders have very little time to patch once a new vulnerability becomes public.
APT29 and Sandworm also remain important names in Russian cyber operations. APT29 is widely associated with stealthy, long-term espionage, while Sandworm is often linked with destructive or infrastructure-focused attacks that can create large-scale disruption.
North Korea-linked APTs
North Korea-linked groups are closely associated with both espionage and financially motivated operations. CISA says North Korean state-sponsored actors have used malware such as BLINDINGCAN, and reporting over time has shown that these actors often target government systems, cryptocurrency, financial infrastructure, and research networks.
Lazarus Group is the best-known example. It has become a symbol of North Korea’s blended cyber strategy, where theft, intrusion, and intelligence gathering all support the regime’s broader strategic needs.
Kimsuky is another important North Korea-linked name. It is often associated with phishing, intelligence collection, and credential theft, especially against policy, academic, and government targets.
Iran-linked APTs
Iran-linked APTs often focus on social engineering, credential theft, and cloud account compromise. Google Cloud’s reporting on APT42 highlights enhanced social engineering schemes, especially against journalists, activists, politicians, and others the Iranian regime may view as politically sensitive.
APT42 is notable because it combines digital intrusion with influence-style tactics. That means the group may not just steal emails or files; it may also use the access to support surveillance, harassment, or information operations.
APT33 and APT35 are also frequently discussed in Iranian cyber reporting. Their activity has included phishing, account compromise, and targeting of strategic sectors such as energy, aerospace, and politically relevant organizations.
Major attack patterns
Although the APT names differ, the tactics often repeat. Phishing remains one of the most common entry points, especially for groups focused on credential theft or initial access.
Malware delivery and post-exploitation frameworks are also common. APT28 used Covenant, APT41 used DUSTPAN and DUSTTRAP, and North Korean actors have used variants like BLINDINGCAN in state-backed campaigns.

Cloud abuse is another major trend. Attackers increasingly hide command-and-control traffic inside legitimate services or use cloud tools for exfiltration, as seen in APT41’s use of OneDrive and Google Workspace-related infrastructure in recent reporting.
Why readers should care
The reason this topic matters is that APTs affect both national security and business security. Government agencies are obvious targets, but so are logistics firms, hospitals, technology companies, and any organization that stores valuable data or supports strategic supply chains.
A single successful intrusion can expose intellectual property, diplomatic communications, personal data, or operational systems. In some cases, the attack is not loud or destructive at first, which makes it harder to detect until the damage is already done.
How to defend against APTs
The best defense starts with visibility. Organizations should monitor authentication logs, endpoint activity, email behavior, and unusual data transfers so they can detect stealthy intrusions early.
The next layer is access control. Multi-factor authentication, least-privilege access, network segmentation, and fast patching are especially important because many APT campaigns still rely on stolen credentials or unpatched software.
Training also matters. Social engineering remains a core tactic for groups like APT42 and Kimsuky, so employees need to recognize suspicious emails, fake login pages, and unusual requests for urgent action.
What This Means for Defenders
APT groups are best understood as country-linked threat actors with distinct goals, but similar methods. China-linked groups often emphasize espionage and supply-chain compromise, Russia-linked groups often combine espionage with disruption, North Korea-linked groups mix intelligence and financial theft, and Iran-linked groups lean heavily on phishing and social engineering.




