By John Qian, Chief Information Security Officer, Aviatrix
The only thing worse than a cyberattacker is a cyberattacker who has learned to be strategic and patient in infiltrating networks: playing the long game to get access and cause damage. The evolving APT threat landscape-driven by smart, resourceful, and patient adversaries-makes it clear that enterprises must elevate their cloud network security strategy in response.
Attackers are getting more creative in their methods. APTs are now targeting the cloud infrastructure itself: shared services, VPNs, and lateral movement paths.
These aren’t quick, opportunistic attacks-they’re prolonged infiltrations, often carried out by highly skilled, nation-state-backed groups.
This blog will explore what APTs are, how they work, and how CISOs can use proactive design and security policies to protect their networks.
What are APTs?
An APT, or Advanced Persistent Threat, is a highly skilled and well-funded cyber adversary. APT groups are:
- Often nation-state sponsored?
- Focused on long-term infiltration and data theft?
- Known for tactics that include zero-day exploits, lateral movement, and persistence
For example, China has achieved “cyber superpower” status, making it increasingly difficult to deter its cyber operations.? There has been a significant increase in zero-day exploit usage by Chinese state-sponsored hackers since 2021.?
According to Sandra Joyce (VP, Google Threat Intelligence), ?these APTs are highly adept at ypassing security controls and remaining undetected for long periods.? Volt Typhoon exemplified this threat, with extended intrusions into U.S. government and critical infrastructure networks.?
These attackers are also skilled in exploiting the “visibility gap“-targeting devices like firewalls and edge infrastructure, where EDR (endpoint protection and response) solutions typically aren’t deployed.?
Key APT Campaigns Targeting Cloud
These APT groups are targeting cloud infrastructure to gain persistence, exfiltrate data, and disrupt operations?.
We’re seeing multiple APT groups focus specifically on cloud infrastructure.?
- Salt Typhoon is targeting telecoms and ISPs.?
- APT31/Zirconium is attacking through malicious email campaigns.?
- APT10, known as Cloud Hopper, is breaching service providers to pivot into enterprise environments.?
- Groups like Silk Typhoon, Sandworm, and Cozy Bear are all showing a consistent pattern: attacking shared services, exploiting multicloud misconfigurations, and persisting inside cloud environments.?
The bottom line: APT campaigns are no longer an on-premises problem. They are a cloud problem now, and CISOs need to address them proactively.
How APT Groups Attack the Cloud
APTs are increasingly targeting the cloud infrastructure itself.? Their goal is persistence instead of just a quick win. ?They want to quietly stay inside your environment for months, even years, gathering information, escalating privileges, moving laterally and exfiltrating sensitive data.? The reality today is that organizations must assume persistence: attackers won’t just break in and leave; they’ll settle in and wait for opportunities.?
They’re exploiting weak points like VPNs, firewalls, and routers, the places traditional EDR tools often can’t see.? And when networks are flat – when there’s little segmentation between workloads – it makes their job even easier.?
This is why CISOs need to implement security strategies like strengthening cloud perimeters, segmenting workloads, and hardening east-west and egress paths to defend their networks.
How an APT Attack Unfolds
Let’s walk through how a typical APT breach unfolds.?
- First, they find a foothold – often through a vulnerable VPN, firewall, or a weak IAM policy.?
- Then comes reconnaissance: they quietly map out the environment, identifying where sensitive assets are located, which accounts have elevated privileges, and what network paths they can exploit.?
- After gathering that intelligence, they escalate privileges, often by stealing credentials or exploiting misconfigurations, and gain admin-level access.?
- Once they have higher permissions, lateral movement becomes easy. They can traverse workloads, pivot between cloud accounts, and dig deeper into your environment.?
- Next is data exfiltration. Attackers zero in on high-value assets like customer databases, intellectual property, or backups.
- Then they begin to transfer that data out, often using encrypted channels or traffic that mimics legitimate behavior.?
- This is where the business damage begins: stolen data, leaked credentials, or regulated assets that trigger fines and investigations.
- Throughout, they manipulate network paths to bypass security controls and avoid detection, staying hidden for long periods.?
Case Study: The Salt Typhoon APT
A real-world example of an APT is Salt Typhoon, a state-sponsored group linked to Chinese intelligence.?? Salt Typhoon has specifically targeted telecoms, ISPs, and cloud environments, exploiting vulnerabilities in routers, firewalls, and VPN appliances to gain an initial foothold.??
What more organizations are now coming to terms with as we talk to customers and prospects:?? even those that had deployed MACsec encryption weren’t fully protected.?? MACsec only encrypts physical links and decrypts traffic at every network hop. That means your data is exposed at multiple points across third-party infrastructure.?? That’s the same infrastructure groups like Salt Typhoon are actively compromising.??
Once traffic is decrypted, attackers can intercept, inspect, and move laterally inside the network.?? Once they gained access, Salt Typhoon deployed GhostSPIDER malware – a stealthy backdoor built for long-term persistence.?? GhostSPIDER allowed them to harvest credentials, monitor traffic, manipulate routing, and establish multiple hidden access channels.”?? ?
The APT MO: Exploiting Network Vulnerabilities
For initial access, the Salt Typhoon APT exploited vulnerabilities across a range of network devices – targeting VPNs, firewalls, and routers specifically.?? Using CVEs from Fortinet, Ivanti, Cisco, Juniper, and Microsoft Exchange Proxy Logon, they compromised perimeter infrastructure, enabling stealthy, long-term access to cloud and hybrid environments.??
The scope of the attack surface is immense-threat actors compromised more than 100,000 routers. While not all vulnerabilities are directly linked to the campaign, the growing pool of potential exploits is concerning. In 2024, the National Vulnerability Database (NVD) recorded over 40,000 new CVEs-a 39% increase from the previous year-offering a broad and expanding arsenal that groups like Salt Typhoon can selectively leverage.
Notably, network edge devices, including VPNs, firewalls, and routers, were among the most frequently exploited, with the top four vulnerabilities of the year affecting these devices. ?
As CISA Director Jen Easterly put it😕 “?Edge devices like routers, firewalls, and switches are really the connective tissue – and the soft underbelly for our adversaries.??”
Salt Typhoon exposed just how fragile the connective tissue of modern infrastructure really is-and why end-to-end encryption at the network layer and strong segmentation within cloud environments are now critical pillars of cyber defense.
Call to Action: Defend Your Network Proactively
The Salt Typhoon campaigns were so significant that in December 2024, multiple government agencies – including CISA, the NSA, and international partners – issued a very rare joint advisory.?? The core of the guidance was clear: organizations must move beyond reactive defenses and proactively harden their cloud and edge environments.??
They emphasized two major themes:??
- First, monitoring and visibility – things like tracking configuration changes, conducting network flow monitoring, and baselining network behavior to detect anomalies early.??
- Second, hardening systems and devices – using out-of-band management, enforcing default-deny access control lists, aggressively segmenting networks, isolating exposed services into DMZs, and ensuring traffic is encrypted end-to-end to the maximum extent possible – not just on physical links.??
This guidance reflects a broader truth: Threats are evolving faster than traditional architectures can keep up.?? There are critical architectural gaps in how most cloud environments are secured today.??
Hackers Exploit Architectural Flaws
Here’s what attackers are exploiting:??
- Edge infrastructure penetration – getting in through VPNs, firewalls, routers that are often overlooked or under-monitored.??
- Man-in-the-middle attacks – intercepting traffic that’s not properly encrypted through the entire cloud path.??
- Lack of network path control – making it easy to reroute or intercept sensitive data.??
- Persistent network access – weak authentication and compromised edge devices allow attackers to stay hidden for months.??
- Lateral movement and privilege escalation – flat networks and misconfigured IAM make it easy for attackers to spread once inside.??
- Data interception and manipulation – attackers can alter workflows and exfiltrate sensitive data during transit.??
- Unrestricted egress traffic – once inside, attackers can steal data with almost no resistance if egress paths aren’t tightly controlled.??
These gaps aren’t isolated; they reinforce each other.?? If you leave just one or two of these openings, attackers can chain them together for a full environment compromise.??
That’s why addressing cloud security today isn’t just about putting up bigger firewalls – it’s about fundamentally redesigning how we protect cloud environments from the inside out.??
Defending Your Network Through Security-First Design Practices
The good news is: CISOs and other network teams can solve these cloud security gaps, but you’ll need a modern, layered approach.??
Here’s what’s required:?
- Automate patching – so vulnerabilities are closed before attackers can exploit them.?
- Implement Least Privilege Access and Zero Trust principles – restricting users, workloads, and devices to exactly what they need, nothing more.?
- Apply network segmentation and egress controls – making sure attackers can’t move freely or exfiltrate sensitive data once inside.?
- Encrypt data in transit – not just between users and clouds, but through the cloud, across VPCs, VNets, regions, and hybrid environments.?
- Enforce strict policy controls across all cloud and network layers – so that security follows the workload, not just the infrastructure.?
- Secure management traffic – encrypting and isolating administrative access so attackers can’t tamper with configurations unnoticed.?
- Enable real-time monitoring and anomaly detection – so you can detect lateral movement, data exfiltration, and privilege abuse before it turns into a full-blown breach.?
Working with engineers, security experts, developers, and DevOps teams, you can fortify your network and design policies that maintain a holistic, comprehensive security posture.
Final Thoughts
These design principles are the foundation for building a resilient, compliant, and attack-ready cloud architecture.? By investing in your networking stack with a resilient, security-first approach, you can defend your network against the patient and long-game attacks of APTs and other threats.
##
ABOUT THE AUTHOR
John Qian is an accomplished security technology leader with over a decade of experience in technical and management roles within dynamic, global, and fast-paced environments. He has a proven track record of building high-performing teams to develop and implement comprehensive security strategies, architectures, and processes across multi-cloud, hybrid, and on-premises systems. Qian has Led the rollout of company-wide security initiatives, including reference architecture, SDL, DevOps Security, IAM/Zero Trust, CI/CD security, training programs, and security risk and compliance frameworks. These efforts have significantly reduced corporate risk, ensured regulatory compliance, and fostered a culture of security throughout the organization.






