SophosLabs’ Gabor Szappanos picked a particular exploit that went after a vulnerability in Microsoft Office. The most infamous APT groups — Plugx, Pitty Tiger, and Inception — were at the lower end of the skills table. In more than half of the samples tested, the exploit code didn’t work at all. None of the groups were able to understand the exploit well enough to adapt it to attack more than one version of Microsoft Office. The results may affect how companies allocate their security resources, particularly when dealing with advanced persistent threats.”]
Source: https://www.csoonline.com/article/2879147/apt-developers-not-as-smart-as-theyre-made-out-to-be.html