Mandiant, now operating as part of Google Cloud, continues to serve as one of the cybersecurity industry’s most authoritative sources of threat intelligence on state-sponsored cyber operations. Recent findings from Mandiant’s threat research teams reveal significant shifts in how nation-state actors conduct espionage, sabotage, and influence operations across global networks.
The Evolving Playbook of Advanced Persistent Threats
Mandiant tracks dozens of advanced persistent threat (APT) groups attributed to nation-states including China, Russia, Iran, and North Korea. According to their latest threat intelligence reports, several of these groups have fundamentally altered their operational approaches in response to improved defensive capabilities across target organizations.
One of the most notable trends is the increasing use of living-off-the-land techniques, where attackers rely on legitimate system administration tools rather than custom malware. Groups such as APT29, attributed to Russian intelligence services, have been observed extensively using PowerShell, WMI, and native cloud management APIs to move laterally through compromised networks while evading endpoint detection solutions.
Supply Chain Targeting Intensifies
Mandiant’s research highlights a sustained increase in supply chain compromises as a preferred initial access vector. Rather than attacking well-defended primary targets directly, threat actors are compromising managed service providers, software vendors, and IT supply chain partners to gain access to multiple downstream victims simultaneously. This approach multiplies the return on investment for sophisticated attack campaigns and complicates attribution efforts.
Cloud Infrastructure as a Battleground
As organizations accelerate their migration to cloud environments, state-sponsored actors have followed. Mandiant has documented multiple campaigns targeting cloud identity providers, exploiting misconfigurations in cloud access management, and abusing OAuth tokens to maintain persistent access to cloud-hosted resources. These techniques represent a significant evolution from traditional on-premises attack methodologies.
The shift to cloud targeting has also changed how Mandiant approaches incident response. Investigators now routinely analyze cloud audit logs, API call patterns, and identity federation configurations alongside traditional forensic artifacts. This expanded scope requires new analytical frameworks and tooling that Mandiant has been developing and integrating into its threat intelligence platform.
Intelligence-Driven Defense Recommendations
Based on these observed trends, Mandiant recommends that organizations adopt several defensive priorities. First, implementing robust identity and access management controls, particularly for cloud environments, reduces the attack surface available to sophisticated adversaries. Second, deploying behavioral detection capabilities that can identify suspicious use of legitimate tools complements traditional signature-based defenses.
Third, organizations should conduct regular threat-informed assessments using frameworks like MITRE ATT&CK to validate that their security controls address the specific techniques employed by relevant threat actors. Mandiant’s threat intelligence feeds integrate directly with major security platforms, enabling automated mapping of current threat activity to organizational defenses.
The Value of Frontline Intelligence
What distinguishes Mandiant’s intelligence is its foundation in frontline incident response work. Every year, Mandiant responds to hundreds of significant breaches, generating firsthand intelligence about attacker behavior that informs its broader threat assessments. This operational grounding ensures that Mandiant’s analysis reflects the real-world tactics defenders encounter rather than theoretical possibilities, making it an essential resource for security teams building intelligence-driven defense programs.




