ZIRCONIUM — APT Profile
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
APT31, Violet Typhoon, Judgment Panda, TA412, Red Keres, Bronze Vinewood, TIDE CASTLE
IntelFusions coverage (3)
- China-linked hackers grow a covert router relay with new backdoors 2026-07-07 · Nation-State
- Walking on APT31 Infrastructure Footprints: Inside China's SOHO Router Spy Network 2026-02-16 · Nation-State
- The Story of Jian: How APT31 Stole and Repurposed an NSA Zero-Day Two Years Before the Shadow Brokers Leak 2026-02-16 · Nation-State
Tools & malware
- DropboxAES RAT malware
- HanaLoader malware
- Metasploit tool
- Mimikatz tool
- Reverse ICMP shell tool
- Trochilus malware
Vendor research
- BRONZE VINEWOOD Threat Profile Secureworks
- APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services Zscaler
- IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders Mandiant
- How Microsoft names threat actors Microsoft
- New cyberattacks targeting U.S. elections Microsoft
- The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day Check Point
Countries linked to this actor
- Sweden targets
- Finland targets
- Lithuania targets
- France targets
- Canada targets
- Belgium targets
- Czech Republic targets
- Russia targets
- Hong Kong targets
- United Kingdom targets