Cyber Threat Report: 'ANALYSIS OF THE APT31 INDICTMENT'

Report Author Harfang Lab
Publication Date 2024-04-16
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets Zirconium , APT31
Related Threat Actors Wuhan Xiaoruizhi Science and Technology Company Limited
Identified CVEs CVE-2017-0005
Victim Sectors Legal Services, Telecommunications, Aerospace, Defense, Journalism, Financial Services, National Government, Ministries of Foreign Affairs, Technology, Manufacturing

Blog post providing analysis of a March 2024 US Department of Justice indictment of 7 hackers associated with APT31. The post details attribution of APT31 to Wuhan XRZ as a front company and linked to the Hubei State Security Department and China's Ministry of State Security. The indictment states that the group (also known as BRONZE VINEWOOD, Zirconium or Judgment Panda) has been active for 14 years, targeting numerous sectors globally. The post details tactics, techniques and procedures used by the group as well as providing limited analysis of associated malware.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1036 Masquerading Defense Evasion
T1598.003 Spearphishing Link Reconnaissance
T1070.006 Timestomp Defense Evasion