THREATOPS Actor Dossier
LIVE ← Dashboard

ZIRCONIUM

G01282 reports
aliases · ZIRCONIUM · APT31 · Violet Typhoon
Export dossier:
2
Reports
10
Techniques
8
Tactics
2
Countries
70%
Hunt coverage
3
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1588.006 (Vulnerabilities), T1053.005 (Scheduled Task), T1059.007 (JavaScript).
  • Primary targeting: CN, US.
  • Newly emerged: 2 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 10 new technique(s), 30 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 70% of 10 observed techniques (3 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

Newly emergedLast 30d: 2 vs 0 prior (+100%)· first reported 2026-09-09 · last 2026-09-09
0
7d
2
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1588.006T1053.005T1059.007T1036T1055T1087.003T1059.001T1589.001T1564.003AML.T0074
Targeting gained
CNUS
New infrastructure
d17053557bb90298f7b115432b4820a248fdbe67337b48c1cd6dd6e7b8073327082a60e149517fa07a52ff23949edee8faa61ce0def6dbca8b7e5943cd0c21f9b32b7feeda1787fccab622dec60ecdf8b7b0cd6539464ab39c6526e499f86d611faa21c55995f42a828606705a7339d58a665c229936e81c51462a23ac25e1bd0e49b7cae7f3a71f8d2201e269c1603f3f9015beb0097d0a3bb0f17400c314e23b71d721c39fad92a44ddd764bbb34afeae44a5d56eda0ac82e06ee609b034306025e67df161c58759dc108e22cb856c228bbf8a1ab955fb66f0844ae2a59432ce2b0d83ded936374a11fca3d3defaf4

Vulnerabilities in this actor's reporting · 3

Overview

Analyst triage
Intelligence summary

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected