ZIRCONIUM
ZIRCONIUM is a China-linked threat actor tracked under multiple aliases including APT31, Bronze Vinewood, Chameleon, Judgement Panda/Judgment Panda, Red Keres, TA412, Violet Typhoon, and Webfans. The provided content links ZIRCONIUM to Microsoft’s Violet Typhoon naming and repeatedly references APT31 as the associated industry name. The actor is described as Chinese government-linked / China-based in the context of SharePoint exploitation reporting. Observed tradecraft in the provided content includes establishing persistence via a Registry Run key named "Dropbox Update Setup" for a malicious Python binary; using Dropbox as command and control to upload and download files, execute arbitrary commands, and exfiltrate stolen data via the Dropbox API; opening a Windows command shell on remote hosts; querying the Windows Registry for proxy settings; capturing processor architecture to register compromised hosts with C2; stealing credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome; and using AES256 with a SHA1-derived key to decrypt exploit code. The content also states that ZIRCONIUM has utilized an ORB (operational relay box) network composed of compromised SOHO routers, IoT devices, and leased VPS infrastructure to proxy traffic. The content further places Violet Typhoon among Chinese state-linked actors observed exploiting SharePoint vulnerabilities against internet-facing SharePoint servers, with Microsoft describing Violet Typhoon as a Chinese nation-state actor that has operated since 2015 and primarily conducts espionage against former government and military personnel, NGOs, think tanks, higher education, media, financial, and health sectors in the United States, Europe, and East Asia. The content also notes exploitation of SharePoint vulnerabilities by China-linked groups including Linen Typhoon and Violet Typhoon to steal intellectual property.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
Associated vulnerabilities
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East shortly after the vulnerability was publicly revealed and patched in July 2025... ToolShell affects on-premise SharePoint servers and gives an attacker unauthenticated access to vulnerable servers, allowing them to remotely execute code and access all content and file systems.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
Microsoft has not confirmed exploitation of CVE-2025-53771; however, CISA assesses exploitation is likely because it can be chained with CVE-2025-53770 to bypass previously disclosed vulnerabilities CVE-2025-49704 and CVE-2025-49706.
ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.
1 more CVE tied to this actor tracked in Mallory.
Observables
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploited SharePoint vulnerabilities to steal intellectual property.
Named threat actor referenced in retrospective threat reporting.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation.
Referenced as a China-affiliated threat actor involved in similar activity targeting messaging app users and compromising individual accounts by bypassing encryption protections in commercial messaging applications.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.