ZIRCONIUM
G01282 reportsaliases · ZIRCONIUM · APT31 · Violet Typhoon
2
Reports
10
Techniques
8
Tactics
2
Countries
70%
Hunt coverage
3
Aliases
Analyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1053.005 (Scheduled Task), T1059.007 (JavaScript).
- Primary targeting: CN, US.
- Newly emerged: 2 report(s) in last 30d vs 0 prior (+100%).
- Recent movement: 10 new technique(s), 30 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 70% of 10 observed techniques (3 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Newly emergedLast 30d: 2 vs 0 prior (+100%)· first reported 2026-09-09 · last 2026-09-09
0
7d
2
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1588.006T1053.005T1059.007T1036T1055T1087.003T1059.001T1589.001T1564.003AML.T0074Targeting gained
CNUSNew infrastructure
d17053557bb90298f7b115432b4820a248fdbe67337b48c1cd6dd6e7b8073327082a60e149517fa07a52ff23949edee8faa61ce0def6dbca8b7e5943cd0c21f9b32b7feeda1787fccab622dec60ecdf8b7b0cd6539464ab39c6526e499f86d611faa21c55995f42a828606705a7339d58a665c229936e81c51462a23ac25e1bd0e49b7cae7f3a71f8d2201e269c1603f3f9015beb0097d0a3bb0f17400c314e23b71d721c39fad92a44ddd764bbb34afeae44a5d56eda0ac82e06ee609b034306025e67df161c58759dc108e22cb856c228bbf8a1ab955fb66f0844ae2a59432ce2b0d83ded936374a11fca3d3defaf4Vulnerabilities in this actor's reporting · 3
- CVE-2026-85046KEV1 rpt
- CVE-2026-85880KEV1 rpt
- CVE-2026-87491KEV1 rpt
Overview
Analyst triage
Intelligence summary
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1588.006 · Vulnerabilitiesconf 652
- T1053.005 · Scheduled Taskconf 601
- T1059.007 · JavaScriptconf 601
- T1036 · Masqueradingconf 601
- T1055 · Process Injectionconf 601
- T1087.003 · Email Accountconf 601
- T1059.001 · PowerShellconf 601
- T1589.001 · Credentialsconf 601
- T1564.003 · Hidden Windowconf 601
- AML.T0074 · Masqueradingconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|