APT31 (ZIRCONIUM) is a Chinese state-aligned threat actor specializing in intellectual property theft.
Analyst brief
APT31 (ZIRCONIUM) is a threat actor assessed to be operating on behalf of the Chinese government, specializing in intellectual property theft. It targets organizations with competitive advantages and upstream providers like law firms and MSPs to enable further intrusions against high-profile assets. Key TTPs include spearphishing links for reconnaissance, execution via Windows Command Shell and Python, persistence through Registry Run Keys, credential harvesting from browsers, and symmetric cryptography for C2. Defenders should focus on email security for credential harvesting campaigns using web bugs, monitor for exploitation of web services and network devices for resource development, and harden systems against privilege escalation techniques.
APT31
ZIRCONIUMJUDGMENT PANDABRONZE VINEWOOD
unknown
FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competetive in its field. Based on available data (April 2016), FireEye assesses that APT31 conducts network operations at the behest of the Chinese Government. Also according to Crowdstrike, this adversary is suspected of continuing to target upstream providers (e.g., law firms and managed service providers) to support additional intrusions against high-profile assets. In 2018, CrowdStrike observed this adversary using spear-phishing, URL “web bugs” and scheduled tasks to automate credential harvesting.
Monitor network traffic to detect exfiltration over C2 channel and block suspicious traffic.
FAQ2
What type of data does APT31 specialize in stealing?+
APT31 specializes in intellectual property theft, focusing on data and projects that make a particular organization competitive in its field.
Why does APT31 target upstream providers according to CrowdStrike?+
According to CrowdStrike, APT31 is suspected of targeting upstream providers, such as law firms and managed service providers, to support additional intrusions against high-profile assets.