APT31 is a China-linked state-sponsored threat actor widely tracked across the industry under aliases including Zirconium, Violet Typhoon, Judgment Panda, Judgement Panda, Bronze Vinewood, Red Keres, TA412, Chameleon, and WebFans. The group is associated with cyber espionage operations and has been observed targeting government, political, diplomatic, defense, technology, and enterprise organizations, as well as internet-facing infrastructure. Reporting also links the actor to exploitation of Microsoft SharePoint vulnerabilities in attacks against exposed on-premises servers. APT31 is known for combining initial access through exploitation of public-facing applications with post-compromise discovery, persistence, credential access, command-and-control tunneling, and privilege escalation. Observed tradecraft includes exploitation for privilege escalation, use of proxying and anonymization infrastructure, host profiling to capture system and processor architecture details, and Windows Registry discovery to obtain configuration data such as proxy settings. Persistence techniques attributed to the group include Registry Run keys and Windows service-based mechanisms. The actor has also been associated with use of remote access and tunneling utilities to conceal outbound communications. The group has been referenced in connection with exploitation of SharePoint flaws including CVE-2025-49704 and CVE-2025-49706 as zero-days, and broader reporting has tied APT31 to exploitation activity involving internet-connected SharePoint servers for initial access and web shell deployment. In ATT&CK terms, activity associated with APT31 includes Exploitation for Privilege Escalation, Setuid and Setgid abuse, Windows Service persistence, Registry discovery, and Multi-hop Proxy behavior. APT31 should be understood as a mature Chinese espionage actor with a long-running operational history, multiple overlapping vendor naming conventions, and tradecraft spanning both bespoke intrusion activity and opportunistic exploitation of high-value edge systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
On July 19, 2025, security researchers and enterprise defenders began tracking a large-scale exploitation campaign targeting on-premises Microsoft SharePoint Servers (CVE-2025-53770). On July 19th, Microsoft confirmed that a zero day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell”. CVE-2025-53770 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 20, 2025.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.
2 more CVEs tied to this actor tracked in Mallory.
238 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Referenced as using Tailscale to quietly tunnel out of Russian IT firms during 2024 and 2025.
Referenced as a threat actor associated with the MITRE ATT&CK technique T1090.003 (Multi-hop Proxy) in the detection annotation for access to anonymizer services.
Exploited SharePoint vulnerabilities to steal intellectual property.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.