#APT

Advanced Persistent Threat infrastructure (URLs, domains, IPs, hashes) attributed to nation-state and criminal threat actors

Subscribe (RSS)


#APT

APT infrastructure (URLs, domains, IPs, hashes)

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #APT

Week

18

IOCs tagged #APT

Month

225

IOCs tagged #APT

Year

1,769

IOCs tagged #APT

Counts as of 2026-07-19. Regenerated daily.

About #APT

  • Definition: umbrella tag for IOCs that researchers attribute to an Advanced Persistent Threat - typically a well-resourced, long-running adversary (nation-state-aligned or organised criminal) with mission-focused targeting and tradecraft.
  • Common attributed groups in corpus: Kimsuky, Lazarus, APT29, APT41, FIN7, MuddyWater, Konni, OilRig and similar. Each has its own per-tag page when volume justifies it; see #Kimsuky and #Lazarus.
  • Detection: behaviour-based detection (atypical lateral movement, persistence in unusual registry locations, custom protocols), Threat Intelligence-fed blocklists, and YARA on signature-light variants. Entry-point indicators are usually phishing or supply-chain compromise.
  • References: MITRE ATT&CK Groups · CISA APT advisories.

Recent IOCs tagged #APT

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/apt.

Date Type Value Source
Jul 17, 02:25 domain studiokyle.kr @byrne_emmy12099
Jul 17, 02:25 url https://studiokyle.kr/package/htmlpurifier/extras/cache/dele... @byrne_emmy12099
Jul 16, 18:31 ip 77.111.101.227 @akaclandestine
Jul 16, 12:48 domain mofa-gov-bd.fetchdrives.info @phatomcandle
Jul 16, 12:48 url https://mofa-gov-bd.fetchdrives.info/f4fa5248/adobe-reader @phatomcandle
Jul 16, 12:48 md5 ae610fc43f44509cf65750e870ecc915 @phatomcandle
Jul 16, 12:48 md5 b19f080084f1a087c2b10e94fe78557f @phatomcandle
Jul 15, 12:41 domain drive-mofa-account-downlaod-folder-production.up.railway.app @phatomcandle
Jul 15, 12:41 url https://drive-mofa-account-downlaod-folder-production.up.rai... @phatomcandle
Jul 15, 12:41 md5 f89e3efebfdee08a5f76ae2e49408301 @phatomcandle

Related tags

Tags that frequently co-occur with #APT.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is APT (Advanced Persistent Threat)?

An Advanced Persistent Threat is a sophisticated, long-running adversary - typically nation-state-aligned or a top-tier criminal organisation - that targets specific verticals or organisations with mission-focused tradecraft. The label originally distinguished targeted, persistent operations from opportunistic commodity malware. MITRE ATT&CK Groups page lists the most-tracked clusters.

Which APT groups produce the most IOCs in this feed?

DPRK-aligned activity (Kimsuky, Lazarus, plus generic DPRK-tagged operations) dominates volume due to active researcher coverage on Twitter/X. Russian-, Iranian- and Chinese-attributed activity also appears regularly. For per-group filtering see the dedicated pages: #Kimsuky, #Lazarus, #DPRK.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. APT-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this APT subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

APT IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).