Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ZIRCONIUM

Also known as: APT31, Violet Typhoon, Hurricane Panda, Black Vine, TEMP.Avengers, Zirconium, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, TA412, zirconia, APT28, tracked as, zirconium dioxide, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris

Description

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)

Goals & Targeting

Targeted Sectors

Defense
Energy
Financial services
Healthcare
Technology
Aerospace & defense
Manufacturing
Government
Financial services
Transportation
Education
Critical infrastructure
Construction
Telecommunications
Media
Maritime
Aerospace
Retail
Aviation
Utilities
Chemical
Nuclear
Mining

Targeted Countries / Regions

US
FR
GB
KR
JP
IN
CN
RU
PL
AE
KZ
UA
BR
IL
TR
RO
PK
TW
BY
NG
SA
MX
ES
IT
DE
NL

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Command & Control
8 techniques
Discovery
5 techniques
Stealth
10 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 9 MD5 Hash 5 Domain 6

References

  1. Microsoft Targeting Elections September 2020 — Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.
  2. Check Point APT31 February 2021 — Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. ics-cert.kaspersky.com — Cited by web research for: APT28
  5. attack.mitre.org — Cited by web research for: T1583
  6. ics-cert.kaspersky.com — Cited by web research for: T1053.005
  7. attack.mitre.org — Cited by web research for: T1190

Intel Summary

51

Techniques

59

Tools

2

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Details

MITRE ID
G0128
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--4283ae19-69c7-4347-a35e-b56f08eb660b
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.