The China-linked advanced persistent threat group APT31 conducted a prolonged cyber espionage campaign against Russian IT companies, particularly those serving government agencies, from at least late 2022 through 2025. The attackers leveraged legitimate Russian cloud services, such as Yandex Cloud, for command-and-control and data exfiltration, blending their malicious traffic with normal network activity to evade detection. They also staged encrypted payloads and commands on social media profiles and timed their operations to coincide with weekends and holidays, when staffing was minimal. In several cases, APT31 maintained undetected access to victim networks for extended periods, with activity surging during the 2023 New Year holidays and continuing into 2024 and 2025. The campaign focused on intelligence gathering to benefit Chinese state interests, targeting contractors and integrators working with Russian government agencies.
Technical analysis by Positive Technologies and corroborated by other security firms revealed that APT31 used a combination of publicly available tools and custom malware, routing commands through popular web platforms to further mask their activity. The group’s operations against Russia are notable given the countries' strategic partnership and the rarity of public reporting on Chinese cyber activity targeting Russian entities. The campaign highlights the increasing sophistication of APT31’s tradecraft, including the use of cloud infrastructure and social media for stealthy command-and-control, as well as the geopolitical implications of Chinese cyber espionage against Russian technology firms involved in sensitive government projects.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky previously reported activity related to the campaign and identified overlaps with a cluster it tracks as EastWind, adding technical context to the intrusions.
Positive Technologies linked a series of cyber-espionage attacks on Russian IT firms to APT31, describing the group’s use of Yandex Cloud, social media, and cloud-based command-and-control to evade detection.
In May 2025, the Czech Republic publicly attributed targeting of its Ministry of Foreign Affairs to APT31, marking a separate official attribution tied to the group.
During 2024–2025, APT31 conducted targeted intrusions against Russian technology organizations, including government contractors and systems integrators. Some compromises reportedly remained undetected for years.
Reporting describes APT31 as an intelligence-focused threat group that has operated since at least 2010 in support of Beijing’s political, economic, and military interests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.