APTs & Supply Chain Attacks
Press Next → or use ← → arrow keys
What Is an Advanced Persistent Threat?
Break the name down: Advanced — custom malware, zero-days, skilled teams. Persistent — they stay hidden for months or years and come back if removed. Threat — a specific, well-funded group with a mission, usually espionage or sabotage.
The APT Lifecycle — Five Quiet Stages
APTs often avoid malware once inside. They use the victim's own admin tools — PowerShell, remote desktop, scheduled tasks — so their activity looks like normal IT work. That is why they are so hard to spot.
How to Recognise an APT
Researchers number groups (APT1, APT28, APT29) and vendors add nicknames like "Fancy Bear" or "Lazarus". The public catalogue of their techniques is MITRE ATT&CK — the encyclopedia every defender should know.
APT Campaigns Worth Knowing
| Campaign | Year | Why it matters |
|---|---|---|
| Stuxnet | 2010 | APT sabotage that physically destroyed Iranian centrifuges |
| APT1 Report | 2013 | Mandiant publicly unmasked a military hacking unit — a first |
| OPM Breach | 2015 | Background-check records of ~21.5 million US employees stolen |
| Bangladesh Bank | 2016 | Lazarus Group stole $81 million through the SWIFT network |
| SolarWinds | 2020 | APT29 espionage through a poisoned software update — next section |
Every campaign stayed hidden for months and was found long after the damage began. Against APTs, detection speed matters as much as prevention.
Supply Chain Attacks — Poison the Well
The victims then infect themselves, by installing a signed, official-looking update from a trusted name. That is a supply chain attack: break one, reach thousands.
Firewalls and antivirus allow trusted vendors by design. When the poison arrives inside a digitally signed update, every normal check says "this is safe".
One Poisoned Update, Thousands of Victims
The same trick works on open-source packages (fake or hijacked npm and PyPI libraries), hardware, and IT service providers. In 2021, one attack on the vendor Kaseya spread ransomware to about 1,500 businesses at once.
SolarWinds — The Textbook Supply Chain Attack
About 18,000 organisations installed it — including US government agencies and major tech firms. The backdoor slept for two weeks, then woke up and let the attackers pick their real targets quietly.
It stayed undetected for around nine months, until the security firm FireEye caught it while investigating its own breach.
Incident Analysis — Detective Work After the Alarm
The output is a timeline and a root cause. Without them, you clean the visible infection but leave the open door untouched — and the attacker walks back in next week.
The Incident Response Cycle
Prepare → Identify → Contain → Eradicate → Recover → Learn — and the lessons feed straight back into better preparation. Analysis (Section 03) powers steps 2 to 4. Lessons learned (next) is step 6.
The Five Questions Every Analysis Must Answer
| Question | Where the answer lives |
|---|---|
| 1. How did they get in? | Email logs, VPN logs, vulnerability scans of exposed systems |
| 2. When did it start? | First malicious event in the timeline — often months before the alarm |
| 3. Where did they go? | Authentication logs, internal network traffic between machines |
| 4. What did they take or change? | File access records, database logs, unusual outbound transfers |
| 5. Are they still inside? | Hunt for backdoors, new accounts, scheduled tasks, persistence tricks |
Every question above is answered from records collected before the incident. If logging is off, the detective arrives at a crime scene that has already been swept clean. Logging is a decision you make today.
Lessons Learned — Turning Pain Into Strength
What SolarWinds Taught the Whole Industry
Assume Breach, Learn Fast
APTs win with patience and stealth, so defenders must hunt, not just block. Supply chain attacks abuse trust, so trust must be verified. And every incident ends the same right way: analyse honestly, find the root cause, and make the same attack impossible tomorrow.
Explore APT techniques on MITRE ATT&CK. Read Mandiant's yearly M-Trends report for real dwell-time data. Study the NIST incident handling guide (SP 800-61). And practise one drill: could your team answer the five questions today?
🕵️ End of tutorial · Press ← to review, or click Restart