APT31
Actor Type | Nation State |
---|---|
Attributed to Nation | China |
Directly Linked Intrusion Sets | Zirconium , Violet Typhoon |
Affiliated Intrusion Sets | Storm-0558 |
Associated Threat Actor | Chinese Ministry of State Security , Wuhan Xiaoruizhi Science and Technology Company Limited |
Associated MITRE ATT&CK Group | ZIRCONIUM (G0128) |
APT31, attributed to China, is a cyber espionage actor. The groups primary focus is to obtain information that can provide the Chinese government and state-owned enterprises with political, economic, and military advantages.
The group targets multiple sectors, including government, international financial organizations, and aerospace and defense organizations.
APT31 is associated with SOGU, LUCKYBIRD, SLOWGYRO, and DUCKFAT malware and has been observed exploiting vulnerabilities in applicationsto compromise victim environments. The group is also reported as making extensive use of compromised routers for command an control (C2) infrastructure.
In 2024 the US government sanctioned multiple Chinese nationals for targeting US critical infrastructure and linked them to APT31. According to the indictment, APT31 is 'a collection of Chinese state-sponsored intelligence officers, contract hackers, and support staff that conduct malicious cyber operations on behalf of the Hubei State Security Department (HSSD).'
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
APT31 Threat Reports
ANALYSIS OF THE APT31 INDICTMENT
Blog post providing analysis of a March 2024 US Department of Justice indictment of 7 hackers associated with APT31. The post details attribution ...