ZIRCONIUM is a China-linked cyber espionage threat actor widely tracked as APT31. Other aliases include Bronze Vinewood, Chameleon, Judgement Panda (also Judgment Panda), Red Keres, TA412, Violet Typhoon, and Webfáns. The group has conducted targeted operations using acquired domain infrastructure, encrypted command-and-control communications, and tooling for remote command-shell access and payload transfer. ZIRCONIUM has stolen credentials from browser password stores and performed host and network-environment reconnaissance, including collection of proxy settings, processor architecture, usernames, and system time. It has also been associated with exploitation for privilege escalation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Warlock and other groups exploited newly discovered vulnerabilities in internet-exposed, unpatched on-premises Microsoft SharePoint servers. The report identifies the SharePoint ToolShell vulnerability as central to the campaign.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
Resource 106, once decompressed, is a driver called hidsvc.sys. It is loaded into the kernel by invoking the EpMe exploit of CVE-2017-0005 (this is the very same exploit that had its logic find its way into the Jian exploit somehow).
2 more CVEs tied to this actor tracked in Mallory.
260 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Observed exploiting the referenced SharePoint vulnerabilities against internet-facing SharePoint servers.
Listed in the detection's Annotations section.
Listed in the detection's APT annotations.
ZIRCONIUM is listed in the detection's ATT&CK annotations for T1068, Exploitation for Privilege Escalation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.