Skip to main content
QUIETLYTIC
Analysis

State-Sponsored Hackers: Tactics, Targets & How to Defend Against Them

The common tactics, sectors, and defense strategies documented in CISA advisories on state-sponsored hackers, mapped to MITRE ATT&CK and real CVE data.

State-Sponsored Hackers: Tactics, Targets & How to Defend Against Them — Analysis research

State-sponsored hackers don’t rely on one signature move — their tactics vary by sponsor and objective, but CISA’s own advisories show clear, recurring patterns across groups. Understanding those patterns, and which sectors they target, is what turns a name like “APT28” from a headline into something a defender can actually plan around.

Common initial access tactics

Spearphishing remains the most frequently documented entry point across state-sponsored campaigns — a crafted email designed to get a specific, targeted individual to click a link or open an attachment, not a mass-blast phishing run. CISA’s advisory on Russian state-sponsored activity against critical infrastructure (AA22-110A) documents both spearphishing and brute-force credential access as recurring entry methods. Exploitation of known, often unpatched vulnerabilities is just as common: CISA’s advisory on APT40 documents rapid exploitation of newly disclosed CVEs, sometimes within days of public disclosure, before organizations have patched. Supply chain compromise is the most consequential variant — APT29’s intrusion into SolarWinds’ Orion software let it reach numerous downstream government and enterprise networks through a single trusted update, documented in our research on the SolarWinds compromise.

Persistence and evasion tactics

Once inside, state-sponsored groups prioritize staying undetected over moving fast. “Living off the land” — using legitimate, pre-installed administrative tools instead of custom malware — is the defining technique CISA associates with China-linked Volt Typhoon’s operations inside U.S. critical infrastructure, precisely because it generates far less anomalous signal for defenders to catch than a novel malware sample would. Groups also reuse and share tooling across operations: frameworks like Cobalt Strike (a legitimate penetration-testing tool repurposed for intrusion) and PlugX (a remote access tool associated with multiple China-linked operations) show up repeatedly in advisories tied to different named groups, which is part of why attribution based on malware alone is unreliable — see our Cobalt Strike and PlugX profiles for what each tool actually does.

Who state-sponsored hackers target

CISA advisories consistently name the same sector clusters: critical infrastructure (energy, water, transportation), defense industrial base contractors, government agencies, telecommunications, and — increasingly — software and IT service providers whose products reach thousands of downstream customers through a single compromise. Targeting also tracks each sponsor’s stated strategic interests: North Korea’s Lazarus Group has repeatedly targeted cryptocurrency exchanges and blockchain companies, documented in a joint CISA/FBI/Treasury advisory, reflecting a financial objective distinct from the pure espionage motive behind groups like APT29. Pre-positioning inside critical infrastructure — establishing quiet, persistent access without immediate disruption — is the pattern CISA has specifically flagged with Volt Typhoon, distinct from traditional espionage or theft.

Mapping tactics to MITRE ATT&CK

Every tactic described above maps to a specific, structured MITRE ATT&CK technique — spearphishing is T1566, exploitation of public-facing applications is T1190, living-off-the-land techniques span several T1059 sub-techniques. Working from the technique ID rather than a narrative description is what lets a defender check their own detection coverage directly against a documented adversary behavior instead of a vendor’s paraphrase of it. Our ATT&CK technique lookup resolves any technique ID or name against MITRE’s own dataset locally in the browser, and our STIX bundle viewer reads a full structured threat-intelligence bundle — the same format MITRE and most CTI tooling exchange data in — without needing to stand up any infrastructure.

How to defend against state-sponsored tactics

Three defensive priorities follow directly from the tactics above. First, patch against CISA’s Known Exploited Vulnerabilities (KEV) catalog specifically, not just high-CVSS scores generally — state-sponsored groups documented in CISA advisories consistently exploit vulnerabilities already confirmed as actively exploited, which is exactly what KEV tracks; see our vulnerability research for coverage traced to NVD and KEV. Second, treat living-off-the-land activity as a detection gap, not a non-issue — since it uses legitimate tools, it requires behavioral detection (unusual use of administrative utilities) rather than signature-based malware detection alone. Third, scrutinize software supply chain dependencies, since a single compromised vendor update can reach every downstream customer at once, as SolarWinds demonstrated.

For background on who these groups are and which governments sponsor them, see our complete guide to state-sponsored hackers, and for profiles of the most active groups currently targeting U.S. organizations, see our roundup of the most dangerous state-sponsored hacker groups.

Frequently Asked Questions

What is the most common way state-sponsored hackers gain initial access? Spearphishing and exploitation of known, often recently disclosed vulnerabilities are the two most frequently documented entry methods across CISA advisories, alongside supply chain compromise in the most consequential cases.

What does “living off the land” mean in a state-sponsored attack? Using legitimate, already-installed administrative tools instead of custom malware to move through a network, which generates far less anomalous signal for defenders — CISA specifically documents this as Volt Typhoon’s primary technique inside U.S. critical infrastructure.

How can a small security team defend against tactics this sophisticated? Start with what’s already actionable: patch against CISA’s KEV catalog first, map your detection coverage against specific MITRE ATT&CK techniques rather than vague threat categories, and treat unusual use of legitimate admin tools as worth investigating, not dismissing.


Grounded in CISA cybersecurity advisories, MITRE ATT&CK, and the National Vulnerability Database (NVD). See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 MITRE ATT&CK
02 Cybersecurity and Infrastructure Security Agency (CISA)
03 National Vulnerability Database (NVD)

Related intelligence


Cross-referenced intelligence


Analyst tools