Back to Field Notes
Threat Intelligence/Field Note

APT Tradecraft Evolution — What's Different in 2026

Living-off-the-cloud has overtaken living-off-the-land. Identity is the front line. Detection content has to keep up.

Author

Aisha Khan

Director, Threat Intelligence

Published

March 5, 2026

Read

10 min

Share
AI-generated illustration of a power turbine control room
AI-generated illustration of a power turbine control room
Key Takeaways
  • 01Shift 1 — Living-off-the-cloud: APT operators have moved from PowerShell/WMI to native cloud APIs, using a victim's IdP, IAM roles, and cloud automation to move laterally and exfiltrate. Endpoint EDR catches little; cloud audit logs catch most — if anyone reads them.
  • 02Shift 2 — Identity as the front line: token theft, OAuth consent attacks, IdP federation abuse, and SAML response forgery now appear at the front of the kill chain, not the back. IdP/IAM detection content should match the depth endpoint detection has had for years.
  • 03Shift 3 — Patient supply-chain access: XZ Utils was a public example of a much wider pattern. Treat critical-dependency maintainers and third-party SaaS administrators as part of your attack surface.
  • 04SOC re-balance: shift content investment toward IdP, cloud audit, and third-party telemetry. Endpoint signal is still essential, but the marginal value of the next endpoint rule is lower than the marginal value of a strong IdP detection.

After investigating dozens of APT-attributed intrusions in 2024-2025, three tradecraft shifts stand out. Each has implications for what defenders should monitor.

Shift 1 — Living-off-the-cloud

APT operators have moved from PowerShell and WMI to native cloud APIs. They use a victim's IdP, IAM roles, and cloud automation to move laterally and exfiltrate. Endpoint EDR catches little of this; cloud audit logs catch most of it — if anyone is reading them.

Shift 2 — Identity as the front line

Token theft, OAuth consent attacks, IdP federation abuse, and SAML response forgery now appear in the front of the kill chain, not the back. Detection content for IdP and IAM events should match the depth that endpoint detection has had for years.

Shift 3 — Patient supply-chain access

The XZ Utils backdoor was a public-facing example of a much wider pattern: long-game access to the software and service supply chain. Defenders should treat critical-dependency maintainers and third-party SaaS administrators as part of their attack surface.

What this means for the SOC

Re-balance content investment toward IdP, cloud audit, and third-party telemetry. The endpoint signal is still essential, but the marginal value of the next endpoint rule is lower than the marginal value of a strong IdP detection.

#APT#Tradecraft#Threat Intel

/WRITTEN_BY

Aisha Khan

Director, Threat Intelligence · Alexa Cybersecurity