APT31 is a China-linked cyberespionage threat actor assessed to operate in support of the Ministry of State Security, including the Hubei State Security Department. It is also tracked as ZIRCONIUM, TA412, Violet Typhoon, Bronze Vinewood, Chameleon, Judgement Panda (Judgment Panda), Red Keres, WebFans, JungleBamboo, and Tide Castle. U.S. authorities have alleged that the group has operated a global espionage and transnational-repression program since at least 2010, targeting government personnel, politicians, dissidents, pro-democracy advocates, organizations critical of the PRC, and strategically significant commercial entities. APT31 has used spearphishing and tailored social-engineering lures for initial access, including messages impersonating journalists, internship applicants, academic contacts, and procurement personnel. Its targeting includes U.S. nongovernmental organizations, mining and commodity-trading firms, aerospace and defense organizations, government entities, telecommunications and information-technology companies, financial and consulting organizations, and research institutions. Reported activity has also targeted entities in Vietnam, Indonesia, Singapore, Norway, Hong Kong, and other locations. The actor has conducted reconnaissance through email tracking and victim profiling, followed by exploitation and malware-enabled collection. Reported capabilities include exploitation of zero-day vulnerabilities, compromise of email and cloud accounts, browser surveillance, credential and session-cookie theft, keylogging, screen capture, browser-data collection, command execution, and data exfiltration. In 2026, TA412 was the first confirmed user of the BlueMoon browser exploit kit, using spearphishing links to target U.S. organizations and deploy the GemStone malicious browser extension. This activity used Chromium browser exploitation and Windows local privilege escalation to install a browser-surveillance backdoor capable of collecting browser credentials, cookies, storage, browsing content, and keystrokes. APT31 operations have also used browser-extension integrity bypasses, scheduled-task persistence, DLL sideloading, process injection, and other defense-evasion techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
The exploit first gains arbitrary read/write within the V8 sandbox through the Type confusion vulnerability (CVE-2026-85046). Google patched CVE-2026-85046 in the Stable Channel update on September 3, moving users to Chrome 152.0.7977.82 or .83.
It then exploits a third vulnerability in the Windows kernel (CVE-2026-85880) to escape Chrome’s sandboxed renderer process and inject code into the Chrome browser process.
Warlock and other groups exploited newly discovered vulnerabilities in internet-exposed, unpatched on-premises Microsoft SharePoint servers. The report identifies the SharePoint ToolShell vulnerability as central to the campaign.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
5 more CVEs tied to this actor tracked in Mallory.
288 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison: it reportedly used the same browser-extension installation approach in a separate campaign involving the BlueMoon exploit kit and the GemStone credential-stealing extension.
Espionage-focused activity using the BlueMoon exploit kit to compromise Chrome and Microsoft Windows through a browser sandbox escape and Windows kernel privilege escalation.
Conducted espionage-oriented attacks using the BlueMoon exploit kit against US NGOs, mining entities, and physical commodity trading firms.
Confirmed user of the BlueMoon Chrome exploit kit in an espionage campaign targeting U.S. non-governmental organizations, mining companies, and commodity traders. The group used phishing messages to deliver a Chrome-to-Windows exploit chain that escapes the browser sandbox, elevates privileges, injects into the Chrome broker process, and downloads and runs payloads using curl.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.