THREAT_ACTOR · G0128
ZIRCONIUM
Also known as: ZIRCONIUM, APT31, Violet Typhoon
Profile
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.
MITRE ATT&CK ↗Techniques
29 ATT&CK techniques attributed to this actor.
T1012 Query RegistryT1016 System Network Configuration DiscoveryT1027.002 Software PackingT1033 System Owner/User DiscoveryT1036 MasqueradingT1036.004 Masquerade Task or ServiceT1041 Exfiltration Over C2 ChannelT1059.003 Windows Command ShellT1059.006 PythonT1068 Exploitation for Privilege EscalationT1082 System Information DiscoveryT1090.003 Multi-hop ProxyT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1124 System Time DiscoveryT1140 Deobfuscate/Decode Files or InformationT1204.001 Malicious LinkT1218.007 MsiexecT1547.001 Registry Run Keys / Startup FolderT1555.003 Credentials from Web BrowsersT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1573.001 Symmetric CryptographyT1583.001 DomainsT1583.006 Web ServicesT1584.008 Network DevicesT1598 Phishing for InformationT1598.003 Spearphishing LinkT1665 Hide Infrastructure
Related corpus activity
10,308 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to ZIRCONIUM.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,308.