ZIRCONIUM

MITRE ATT&CK: G0128 View on attack.mitre.org

Aliases: APT31, Violet Typhoon, ZIRCONIUM, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, TA412, Zirconium, Chameleon, WebFans

First seen
2017-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
expert
Resource level
government
Actor type
nation-state
Related IoCs
18 (17 malicious)
Last IoC activity
2026-07-30 14:46:07
Profile updated
2026-07-07 12:34:47

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment

Targeted regions: country_code:us country_code:cn

Context

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.

Recent IoC activity

17 malicious indicators in Maltiverse are attributed to ZIRCONIUM (G0128). The 17 most recently updated:

Detection coverage

  • 326 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Phishing for Information (attack-pattern)
  • Query Registry (attack-pattern)
  • Hide Infrastructure (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Web Services (attack-pattern)
  • Network Devices (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Python (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Domains (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Masquerading (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Software Packing (attack-pattern)
  • Malicious Link (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)

Exploited vulnerabilities

  • CVE-2017-0005 (vulnerability)

Reports & references

  • Mandiant — Apt Groups (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.com — Yir Cyber Threats Report Download (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Microsoft — Rwmfii (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • proofpoint.com — Above Fold And Your Inbox Tracing State Aligned Activity Targeting Journalists (report)
  • CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
  • ncsc.gov.uk — Uk Allies Hold Chinese State Responsible For Pervasive Pattern Of Hacking (report)
  • gov.uk — Uk And Allies Hold Chinese State Responsible For A Pervasive Pattern Of Hacking (report)
  • foreignminister.gov.au — Australia Joins International Partners Attribution Malicious Cyber Activity China (report)
  • consilium.europa.eu — Declaration By The High Representative On Behalf Of The Eu Urging China To Take Action Against Malicious Cyber Activities Undertaken From Its Territory (report)
  • Microsoft — Detecting And Mitigating Elevation Of Privilege Exploit For Cve 2017 0005 (report)
  • duo.com — Apt Groups Moving Down The Supply Chain (report)
  • go.recordedfuture.com — Cta 2019 0206 (report)
  • redalert.nshc.net — Threat Actor Targeting Hong Kong Activists (report)
  • twitter.com — 1201876664667582466 (report)
  • secureworks.com — Bronz Vinewood Uses Hanaloader To Target Government Supply Chain (report)
  • secureworks.com — Bronze Vinewood Targets Supply Chains (report)
  • secureworks.com — Bronze Vinewood (report)
  • research.checkpoint.com — The Story Of Jian (report)
  • supo.fi — Suojelupoliisi Tunnisti Eduskuntaan Kohdistuneen Kybervakoiluoperaation Apt31 Ksi (report)
  • poliisi.fi — Eduskunnan Tietojarjestelmiin Kohdistuneen Tietomurron Tutkinnassa Selvitetaan Yhteytta Apt31 Toimijaan (report)
  • pst.no — Etterforskningen Av Datanettverksoperasjonen Mot Fylkesmannsembetene Er Avsluttet (report)
  • nrk.no — Pst Har Etterretning Om At Kinesisk Gruppe Stod Bak Dataangrep Mot Statsforvaltere 1.15540601 (report)

Attributed from

  • FLORAHOX Activity (campaign)

External references