KELA REPORT

APT Groups And Their Presence In The Cybercrime Ecosystem [REPORT]

Despite the aura of sophistication surrounding APT groups, and although it is difficult to identify them in cybercrime sources, the cybercrime ecosystem is an important resource for APT groups when it comes to their operations.

Share:

KELA report cover: APT Groups And Their Presence In The Cybercrime Ecosystem

APT attacks are conducted by highly sophisticated threat actors and are commonly associated with state-sponsored groups. These adversaries have emerged as a significant concern, and the ability to effectively identify and mitigate APT attacks remains a pressing issue for many organizations and countries.

Despite the aura of sophistication surrounding APT groups, and although it is difficult to identify them in cybercrime sources, the cybercrime ecosystem (forums, marketplaces, Telegram channels, etc.) is an important resource for APT groups when it comes to their operations. The cybercrime underground platforms enable the APT groups to obtain tooling to use in their attack chain, gather information during reconnaissance, leak or sell victim data to damage victim’s reputation, recruit skilled actors and more.

In this report, we show how APT groups not only access standard cybercrime sources, but are their active participants, as these sources are important in ensuring that their operations run successfully. Furthermore, we outline the importance of implementing recommendations for protecting an organization against APT attacks.

Key Report Highlights:

  • Why APT groups use cybercrime forums, markets and Telegram: sourcing tools, reconnaissance, leaking or selling data, and recruitment
  • Malware-as-a-service in APT attack chains: Warzone RAT (APT-C-36, Confucius, YoroTrooper), DarkCrystal and Colibri Loader (UAC-0113, linked to Sandworm) and BitRAT
  • How APTs use open-source tooling, leaked credentials, infostealer logs and purchased remote access in their campaigns
  • Publicly disclosed CVEs and exploits for sale as a resource for state-sponsored actors
  • Case studies: Emennet Pasargad’s data leaking, Bronze Starlight’s ransomware leak sites and Pioneer Kitten selling access on a cybercrime forum

Download the Report

Related Resources

KELA and Fujitsu enter into a cybersecurity collaboration agreement to accelerate Active Cyber Defense in Japan

KELA and Fujitsu Enter into Cybersecurity Collaboration Agreement

Abstract lattice graphic showing where AI provider monitoring stops, cover image for the KELA AI Cybercrime Report Q4 2026

KELA AI Cybercrime Report Q4 2026: Inside the criminal market for adversarial AI

KELA on-demand webinar banner: The TeamPCP arrests, from the inside, with Ben Kapon and Jimmy

The TeamPCP arrests, from the inside