APT31

Actor Type Nation State
Attributed to Nation China
Directly Linked Intrusion Sets Zirconium , Violet Typhoon
Affiliated Intrusion Sets Storm-0558
Associated Threat Actor Chinese Ministry of State Security , Wuhan Xiaoruizhi Science and Technology Company Limited
Associated MITRE ATT&CK Group ZIRCONIUM (G0128)

APT31, attributed to China, is a cyber espionage actor. The groups primary focus is to obtain information that can provide the Chinese government and state-owned enterprises with political, economic, and military advantages.

The group targets multiple sectors, including government, international financial organizations, and aerospace and defense organizations.

APT31 is associated with SOGU, LUCKYBIRD, SLOWGYRO, and DUCKFAT malware and has been observed exploiting vulnerabilities in applicationsto compromise victim environments. The group is also reported as making extensive use of compromised routers for command an control (C2) infrastructure.

In 2024 the US government sanctioned multiple Chinese nationals for targeting US critical infrastructure and linked them to APT31. According to the indictment, APT31 is 'a collection of Chinese state-sponsored intelligence officers, contract hackers, and support staff that conduct malicious cyber operations on behalf of the Hubei State Security Department (HSSD).'

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

APT31 Threat Reports

Report

ANALYSIS OF THE APT31 INDICTMENT

Blog post providing analysis of a March 2024 US Department of Justice indictment of 7 hackers associated with APT31. The post details attribution ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.

ATT&CK ID Title Associated Tactics
T1036 Masquerading Defense Evasion
T1598.003 Spearphishing Link Reconnaissance
T1070.006 Timestomp Defense Evasion