#APT

Advanced Persistent Threat infrastructure (URLs, domains, IPs, hashes) attributed to nation-state and criminal threat actors

Subscribe (RSS)


#APT

APT infrastructure (URLs, domains, IPs, hashes)

Subscribe (RSS)


IOCs by window

Today

3

IOCs tagged #APT

Week

8

IOCs tagged #APT

Month

103

IOCs tagged #APT

Year

1,632

IOCs tagged #APT

Counts as of 2026-09-18. Regenerated daily.

About #APT

  • Definition: umbrella tag for IOCs that researchers attribute to an Advanced Persistent Threat - typically a well-resourced, long-running adversary (nation-state-aligned or organised criminal) with mission-focused targeting and tradecraft.
  • Common attributed groups in corpus: Kimsuky, Lazarus, APT29, APT41, FIN7, MuddyWater, Konni, OilRig and similar. Each has its own per-tag page when volume justifies it; see #Kimsuky and #Lazarus.
  • Detection: behaviour-based detection (atypical lateral movement, persistence in unusual registry locations, custom protocols), Threat Intelligence-fed blocklists, and YARA on signature-light variants. Entry-point indicators are usually phishing or supply-chain compromise.
  • References: MITRE ATT&CK Groups · CISA APT advisories.

Recent IOCs tagged #APT

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/apt.

Date Type Value Source
Sep 18, 00:35 url http://185.235.137.35:9000 @G60930953
Sep 18, 00:35 ip 185.235.137.35 @G60930953
Sep 18, 00:35 sha256 a6ceacda670b88e8a8ec9ff5da6a77d9f1c896d6479b2dadb700474a8c40... @G60930953
Sep 16, 10:00 domain requires1.dynuddns.net @phatomcandle
Sep 16, 10:00 url http://requires1.dynuddns.net @phatomcandle
Sep 16, 10:00 url http://101.36.114.215 @phatomcandle
Sep 16, 10:00 ip 101.36.114.215 @phatomcandle
Sep 15, 04:54 ip 101.35.219.220 @phatomcandle
Sep 10, 10:00 domain signning.cloud @phatomcandle
Sep 10, 10:00 url http://signning.cloud @phatomcandle

Related tags

Tags that frequently co-occur with #APT.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is APT (Advanced Persistent Threat)?

An Advanced Persistent Threat is a sophisticated, long-running adversary - typically nation-state-aligned or a top-tier criminal organisation - that targets specific verticals or organisations with mission-focused tradecraft. The label originally distinguished targeted, persistent operations from opportunistic commodity malware. MITRE ATT&CK Groups page lists the most-tracked clusters.

Which APT groups produce the most IOCs in this feed?

DPRK-aligned activity (Kimsuky, Lazarus, plus generic DPRK-tagged operations) dominates volume due to active researcher coverage on Twitter/X. Russian-, Iranian- and Chinese-attributed activity also appears regularly. For per-group filtering see the dedicated pages: #Kimsuky, #Lazarus, #DPRK.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. APT-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this APT subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

APT IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).