A technical characterization of APTs by leveraging public resources
Advanced persistent threats (APTs) have rocketed over the last years. Unfortunately, their technical characterization is incomplete--it is still unclear if they are advanced usages of regular malware or a different form of malware. This is key to develop an effective cyberdefense. To address this issue, in this paper we analyze the techniques and tactics at stake for both regular and APT-linked malware. To enable reproducibility, our approach leverages only publicly available datasets and analysis tools. Our study involves 11,651 regular malware and 4686 APT-linked ones.