Living-off-the-land (LotL) techniques
Deployment of custom-developed backdoors/implants
Use of compromised legitimate servers for C2 infrastructure
Spear-phishing for initial access
Credential harvesting
Operational security (OPSEC) focused infrastructure rotation