Walking on APT31 Infrastructure Footprints: Inside China's SOHO Router Spy Network

APT31's Operational Relay Infrastructure: How China's Cyber Spies Build Their Shadow Network

A deep-dive investigation by SEKOIA.IO's Cyber Threat Intelligence team has pulled back the curtain on the infrastructure architecture used by APT31 — the Chinese state-sponsored group also tracked as Zirconium and Judgment Panda — revealing a sprawling network of compromised SOHO routers that doubles as both proxy layer and command-and-control backbone.

The SOHO Router Play

APT31 has been leveraging compromised small office/home office (SOHO) routers as Operational Relay Boxes (ORBs) since at least November 2019, when a backdoor sample targeting these devices first surfaced on VirusTotal (MD5: 77c73b8b1846652307862dd66ec09ebf). SEKOIA researchers identified Pakedge, Mikrotik, Netgear, QNAP, and NEC devices among the compromised hardware, though the exact exploitation methods remain unknown — likely a combination of known and zero-day vulnerabilities.

These ORBs serve a triple purpose: frontal attack proxies, active and passive reconnaissance platforms, and C2 servers for downstream implants deployed on victim networks.

Infrastructure Fingerprinting

The research team developed a set of heuristics to track APT31's evolving infrastructure. Key characteristics of their C2 domains include:

Scale of the Discovery

Following ANSSI's publication of APT31-related indicators in mid-2021, SEKOIA's team cross-referenced passive DNS data against the fingerprinted SOHO router population — devices that expose administration panels, specific TLS certificates, or distinctive service banners. The result: nearly 50 IP addresses and 34 domain names newly attributed to the group's operational infrastructure, with a single confirmed overlap at www.fwcheck[.]com.

Attribution and Geopolitical Context

APT31 has been active since at least 2013, operating in alignment with the strategic intelligence priorities of the People's Republic of China. The group gained fresh attention in July 2021 when the UK government formally attributed APT31's activities to China's Ministry of State Security (MSS), a statement echoed nearly simultaneously by EU authorities who linked the group to significant cyberattacks against European industries.

According to Microsoft's tracking data covering July 2020 to June 2021, China-based threat actors demonstrated the strongest interest in targeting critical infrastructure compared to all other nation-state threats observed during that period.

Authorities have also raised the possibility that APT31 members are contractors working directly for the MSS, or operatives within the People's Liberation Army's Strategic Support Force — a designation that would place them among China's most institutionalized offensive cyber units.

Attack Vectors

While the infrastructure findings are novel, APT31's intrusion methods remain consistent with prior reporting: spear-phishing emails, SQL injection, and credential theft for initial access, followed by use of legitimate services — GitHub for payload hosting and Dropbox API for C2 communications — to blend into normal network traffic and bypass perimeter defenses.

Read the full analysis on IntelFusions