4 ms·
Historically the term Advanced Persistent Threat has been used to refer to groups that appear to be a part of some kind of well funded/organized entity. It does
by phaus 7y ago
Historically the term Advanced Persistent Threat has been used to refer to groups that appear to be a part of some kind of well funded/organized entity. It doesn't have much to do with the actual sophistication of the attack. However, an unusual level of sophistication could potentially be a piece of evidence that indicates a significant amount of resources one would only expect to see in a large company or government operation.
Also, in this particular claim Symantec said the attacker used proprietary malware. Does't guarantee that it's advanced but that is something most small groups or individuals don't bother with.
There are, of course, exceptions to everything. That's why it should ideally take a good amount of evidence gathered over a significant period of time to determine whether any given group is likely to be an APT.
Another thing to consider is that even an advanced attacker gains nothing by using their most sophisticated techniques when drive-by downloads and malicious email links/attachments still work so well in 2019 that they account for the overwhelming majority of major data breaches.