Home/Threat Actor/APT31
Threat Actor

APT31

apt31_zirconium · china · active since 2010

APT31 (Zirconium / Violet Typhoon / Judgment Panda / BRONZE VINEWOOD / Altaire / G0128) is a Chinese state-sponsored cyber- espionage actor attributed to the People's Republic of China Ministry of State Security, Hubei State Security Department, operating from Wuhan via the front company Wuhan Xiaoruizhi Science and Technology Company (Wuhan XRZ), formally established by the March 25, 2024 US DOJ indictment of seven Chinese nationals, US Treasury OFAC sanctions, a Rewards for Justice $10M bounty, and a coordinated UK government attribution and sanctions package.

active since 2010 across approximately 14 years of operations, APT31 targets US government, Congress, White House staff, US Naval War College CMSI, the 2020 Biden presidential campaign, UK Electoral Commission (compromise assessed 'highly likely' 2021-2022), UK parliamentarians ('almost certain' reconnaissance), Inter-Parliamentary Alliance on China (IPAC) members, US-based Chinese dissidents and democracy activists, and critical infrastructure in defense, energy, telecommunications, and financial services.

defining tradecraft includes the 'Jian' implant, APT31's pre-Shadow- Brokers clone of an Equation Group DoublePulsar/EpMe zero-day built from captured network traffic (Check Point Research 'The Story of Jian', February 2021), and pioneering operation of ORB (Operational Relay Box) mesh proxy networks built from compromised home and SOHO routers (early disclosed July 2021, formalized in Mandiant's May 2024 'IOC Extinction' report).

china confidence: high 21 aliases MITRE ATT&CK G0128 ↗

Profile

APT31 is a Chinese state-sponsored cyber-espionage actor formally attributed to the People's Republic of China Ministry of State Security (MSS), Hubei State Security Department (HSSD), operating from Wuhan via the MSS front company Wuhan Xiaoruizhi Science and Technology Company (Wuhan XRZ, established by HSSD in 2010) with support from Wuhan Liuhe. The US Department of Justice's March 25, 2024 indictment of seven Chinese nationals (Cheng Feng, Ni Gaobin, Peng Yaowen, Sun Xiaohui, Weng Ming, Xiong Wang, Zhao Guangzong), coordinated with US Treasury OFAC sanctions, a Rewards for Justice $10M bounty, and parallel UK government attribution and sanctions, covered approximately 14 years of cyber operations. Microsoft tracks the group as Violet Typhoon.

CrowdStrike as Judgment Panda.

Secureworks as BRONZE VINEWOOD. APT31's defining strategic role is political-intelligence and democracy-targeting espionage in service of MSS objectives. The documented victim set spans an unusually broad cross- section of Western democratic institutions: the White House (staff), US Departments of Justice, Commerce, Treasury, and State.

members of the US Congress including both Democratic and Republican Senators.

the US Naval Academy.

the US Naval War College's China Maritime Studies Institute.

the 2020 Biden presidential campaign.

the UK Electoral Commission (compromised 2021-2022, 'highly likely' per UK Government); UK parliamentarians ('almost certain' reconnaissance per UK Government)

members of the Inter-Parliamentary Alliance on China (IPAC)

critics of Beijing's Hong Kong, Tibet, and Xinjiang policies.

and US-based Chinese dissidents and democracy activists. Two technical tradecraft hallmarks distinguish APT31. First, the 'Jian' implant, Check Point Research's February 2021 'The Story of Jian' disclosed that APT31 captured an Equation Group zero-day (DoublePulsar / EpMe, CVE-2017-0005) from observed network traffic in 2014 and built a clone implant ('Jian') that was used operationally for years before the 2017 Shadow Brokers leak made the original public. This remains one of the clearest documented examples of state-on- state cyber-weapon capture and reuse. Second, APT31 is among the earliest and most prolific operators of ORB (Operational Relay Box) networks, mesh proxy infrastructure built from compromised home routers (notably Pakedge devices in the original 2021 disclosure) and SOHO devices that disguise attacker origin and substantially raise the IOC-management cost for defenders. The May 2024 Mandiant 'IOC Extinction' report formalized the ORB concept and cited APT31 as a pioneering operator. Additional notable tradecraft: 'two-band' initial-access via tracking-link spear-phishing (over 10,000 tracking emails sent between June-September 2018 alone, per the indictment, impersonating prominent US journalists)

targeting via subsidiaries, MSPs, and personal accounts of spouses of high- value targets.

sustained use of cracked Cobalt Strike; development of in-house implants (RAWDOOR, DropDoor) alongside shared Chinese-cluster tooling (PlugX, ShadowPad).

Aliases

21
apt31zirconiumviolet typhoonjudgment pandajudgement pandabronze vinewoodaltairered kereshurricane pandake3chang_clustermss hubeihubei state security departmenthssdwuhan xrzwuhan xiaoruizhiwuhan xiaoruizhi science and technology武汉晓睿智科技wuhan liuheg0128apt 31apt-31

Notable Campaigns

13
2024Mandiant ORB Networks IOC Extinction Report (May 2024)
2024US Rewards for Justice $10M Bounty on APT31 Operators (March 2024)
2024US DOJ Indictment of Seven APT31 Operators (March 25, 2024)
2021-2024Inter-Parliamentary Alliance on China (IPAC) Member Targeting
2021-2022UK Electoral Commission Compromise (2021-2022, attributed March 2024)
2021Mesh of Home Routers, Early ORB Network Tradecraft (Sekoia / Catalin Cimpanu, July 2021)
2021UK Parliamentarians Reconnaissance (2021)
2020US Presidential Campaign Targeting (Google TAG October 2020)
2020COVID-19 Vaccine Theme and Legitimate Service Abuse (Zscaler October 2020)
2018Texas Energy Company Attack (2018)
2014-2017Jian, APT31's Clone of Equation Group EpMe/DoublePulsar (2014-2017)
2010-2024US Naval War College China Maritime Studies Institute Targeting
2010-2024Multi-Year Targeting of US Critical Sectors (per March 2024 Indictment)

Attribution & Reporting

Attributed by
US Department of JusticeUS Department of StateUS Department of Treasury (OFAC)FBICISANSAUS Rewards for Justice programUK GovernmentUK Foreign Commonwealth and Development OfficeUK NCSCUK Electoral CommissionEuropean UnionFive EyesNew Zealand Government Communications Security Bureau (GCSB)MicrosoftMandiantGoogle Cloud Threat IntelligenceGoogle Threat Analysis Group (TAG)Check Point ResearchCrowdStrikeTrend MicroKasperskyCisco TalosSecureworks Counter Threat UnitSentinelOneHarfangLabZscaler ThreatLabzVolexitySOCRadarAnomaliPositive Technologies
Key reporting
reportUS DOJ Indictment: USA v. Cheng Feng et al. (March 25, 2024), Seven Wuhan XRZ Operators
reportUS Treasury OFAC: Designation of Wuhan XRZ and Two APT31 Operators (March 25, 2024)
reportUS Department of State / Rewards for Justice: $10M Bounty on APT31 Operators (March 2024)
reportUK Government / FCDO: UK Holds China State-Affiliated Organisations Responsible for Malicious Cyber Activity (March 25, 2024)
reportUK NCSC: UK and Allies Call Out China State-Affiliated Actors for Malicious Cyber Targeting (March 2024)
reportCheck Point Research: The Story of Jian, How APT31 Stole and Used an Unknown Equation Group 0-Day (February 2021)
reportGoogle TAG (Shane Huntley): How We're Tackling Evolving Online Threats (October 2020)
reportZscaler ThreatLabz: APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services (October 2020)
reportCatalin Cimpanu / The Record: Chinese Hacking Group APT31 Uses Mesh of Home Routers to Disguise Attacks (July 2021)
reportSekoia: Sekoia.io Uncovers the Target List of an APT31 Cluster
reportMandiant: IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders (May 2024)
reportMicrosoft: Violet Typhoon Threat Actor Naming Mapping
reportHarfangLab: Analysis of the APT31 Indictment (April 2024)
reportSOCRadar: Dark Web Profile, APT31
reportEuRepoC: APT Profile, APT 31

Operational

State sponsor

People's Republic of China Ministry of State Security (MSS), Hubei State Security Department (HSSD). Operates from Wuhan, Hubei Province via MSS front company Wuhan Xiaoruizhi Science and Technology Company (Wuhan XRZ), established by HSSD in 2010, with support from Wuhan Liuhe. Formally attributed via March 25, 2024 US DOJ indictment of seven Chinese nationals and a coordinated multi-government attribution statement.

Motivations
espionage, intelligence_gathering, political_intelligence, intellectual_property_theft, election_interference_reconnaissance, dissident_targeting, regime_critic_surveillance, economic_advantage, covid_research_theft, five_year_plan_alignment, critical_infrastructure_reconnaissance
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)35/60 · 58%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin