Cyber threat actor
APT31
MSS, Wuhan State Security Bureau · active since 2010
Intellectual property and political intelligence collection. Indicted by DOJ in 2024 for targeting US political dissidents, journalists, and members of IPAC.
Aliases
ZirconiumJudgment PandaViolet Typhoon
Primary targets
Politicians Journalists Think tanks Aerospace Defense
MITRE ATT&CK techniques
3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1566.002 Spearphishing Link (tracking pixel) | Sent reconnaissance emails with tracking pixels to confirm address, OS, and IP of targets before delivering payloads. | IPAC parliamentarians, journalists, dissidents | DOJ APT31 indictment |
| Credential Access | T1110 Brute Force / Router compromise | Compromised home and SOHO routers of targets to harvest credentials and intercept traffic. | - | DOJ APT31 indictment |
| Collection | T1114.002 Remote Email Collection | Targeted mailbox exfiltration from Microsoft 365 tenants of think tanks and aerospace firms. | - | DOJ APT31 indictment |
Curated incidents
- 2024-03-25·Government / Civil Society·United States, UK, EUDOJ indicts 7 APT31 hackers for targeting IPAC members
Tracking-pixel spearphish campaign against parliamentarians and journalists.
Live feed mentions
- Tue, 22 Jul 2025 20:00:00 GMT · Microsoft Threat IntelligenceMicrosoft attributes on-premises SharePoint exploitation to Chinese state actors