ZIRCONIUM
MITRE ATT&CK: G0128 View on attack.mitre.org
Aliases: APT31, Violet Typhoon, ZIRCONIUM, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, TA412, Zirconium, Chameleon, WebFans
- First seen
- 2017-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- expert
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 18 (17 malicious)
- Last IoC activity
- 2026-07-30 14:46:07
- Profile updated
- 2026-07-07 12:34:47
Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment
Targeted regions: country_code:us country_code:cn
Context
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.
Recent IoC activity
17 malicious indicators in Maltiverse are attributed to ZIRCONIUM (G0128). The 17 most recently updated:
Detection coverage
- 326 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- Phishing for Information (attack-pattern)
- Query Registry (attack-pattern)
- Hide Infrastructure (attack-pattern)
- Windows Command Shell (attack-pattern)
- Web Services (attack-pattern)
- Network Devices (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Python (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Time Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Spearphishing Link (attack-pattern)
- Spearphishing Link (attack-pattern)
- Domains (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Masquerading (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Software Packing (attack-pattern)
- Malicious Link (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
Exploited vulnerabilities
- CVE-2017-0005 (vulnerability)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.com — Yir Cyber Threats Report Download (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Microsoft — Rwmfii (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- proofpoint.com — Above Fold And Your Inbox Tracing State Aligned Activity Targeting Journalists (report)
- CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
- ncsc.gov.uk — Uk Allies Hold Chinese State Responsible For Pervasive Pattern Of Hacking (report)
- gov.uk — Uk And Allies Hold Chinese State Responsible For A Pervasive Pattern Of Hacking (report)
- foreignminister.gov.au — Australia Joins International Partners Attribution Malicious Cyber Activity China (report)
- consilium.europa.eu — Declaration By The High Representative On Behalf Of The Eu Urging China To Take Action Against Malicious Cyber Activities Undertaken From Its Territory (report)
- Microsoft — Detecting And Mitigating Elevation Of Privilege Exploit For Cve 2017 0005 (report)
- duo.com — Apt Groups Moving Down The Supply Chain (report)
- go.recordedfuture.com — Cta 2019 0206 (report)
- redalert.nshc.net — Threat Actor Targeting Hong Kong Activists (report)
- twitter.com — 1201876664667582466 (report)
- secureworks.com — Bronz Vinewood Uses Hanaloader To Target Government Supply Chain (report)
- secureworks.com — Bronze Vinewood Targets Supply Chains (report)
- secureworks.com — Bronze Vinewood (report)
- research.checkpoint.com — The Story Of Jian (report)
- supo.fi — Suojelupoliisi Tunnisti Eduskuntaan Kohdistuneen Kybervakoiluoperaation Apt31 Ksi (report)
- poliisi.fi — Eduskunnan Tietojarjestelmiin Kohdistuneen Tietomurron Tutkinnassa Selvitetaan Yhteytta Apt31 Toimijaan (report)
- pst.no — Etterforskningen Av Datanettverksoperasjonen Mot Fylkesmannsembetene Er Avsluttet (report)
- nrk.no — Pst Har Etterretning Om At Kinesisk Gruppe Stod Bak Dataangrep Mot Statsforvaltere 1.15540601 (report)
Attributed from
- FLORAHOX Activity (campaign)
External references
- mitre-attack — G0128
- APT31
- Violet Typhoon
- Microsoft Targeting Elections September 2020
- Check Point APT31 February 2021
- Microsoft Threat Actor Naming July 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy