APT31 is a China-linked cyber-espionage threat actor active since at least 2010 and widely tracked under aliases including Altaire, Bronze Vinewood, Judgement Panda, PerplexedGoblin, RedBravo, Red Keres, Violet Typhoon, and formerly Zirconium. The cluster name EastWind has been noted as overlapping with activity attributed to APT31. The group is assessed to conduct intelligence collection in support of Beijing and state-owned enterprises, seeking political, economic, and military advantage. APT31 has targeted government entities and a broad set of strategic sectors including financial services, aerospace and defense, high technology, construction and engineering, telecommunications, media, insurance, and IT service providers. Reported activity in 2024–2025 included targeted intrusions against Russia’s IT sector, especially government contractors and systems integrators, as well as targeting of the Czech Ministry of Foreign Affairs. The actor uses spear-phishing for initial access and has demonstrated long-term, stealthy persistence inside victim environments, in some cases remaining undetected for years. Tradecraft includes use of shortcut-based malware delivery, DLL side-loading, scheduled-task persistence masquerading as legitimate software, reconnaissance tooling, browser credential and cookie theft, file discovery, and collection of locally stored user data. APT31 has also used malicious IIS components for credential theft, Linux and Golang backdoors, encrypted tunneling through VPN and developer tunneling services, and cloud- and social-media-based command-and-control channels to blend with normal traffic and support exfiltration. Its operations show a strong emphasis on defense evasion, post-exploitation flexibility, and covert data theft rather than disruptive or financially motivated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.