APT
/eɪ piː tiː/ · Abbreviation · Security & Infosec · Origin: 2006
Definitions
Advanced Persistent Threat — a prolonged, targeted cyberattack in which an attacker (often state-sponsored) gains and maintains unauthorized access to a network, remaining undetected for months or years.
In plain English: A highly skilled hacking group — often backed by a government — that breaks into a network and stays hidden for a long time, quietly stealing data.
Also the name of a package management tool in Debian/Ubuntu Linux (Advanced Package Tool). Context determines meaning: in a security briefing, APT means a sophisticated attacker; in a DevOps chat, 'apt install' means installing software.
Example: 'When the security team says APT and the ops team says apt, they're having very different conversations about very different threats.'
Source: homonym / Linux tooling
Etymology
- 2006
- U.S. Air Force analysts coin 'Advanced Persistent Threat' to describe Chinese state-sponsored intrusions without naming China directly
- 2010
- Google discloses Operation Aurora, attributed to APT groups, making the term mainstream in cybersecurity
- 2013
- Mandiant publishes the APT1 report, publicly linking a specific PLA unit to years of cyber espionage