The United States and United Kingdom publicly attributed long-running cyberespionage campaigns to APT31, a China state-affiliated group linked to the Ministry of State Security. UK authorities said the actors compromised the Electoral Commission’s systems and accessed electoral-register data, while also conducting reconnaissance against parliamentarians critical of China. The activity targeted UK democratic institutions, lawmakers, dissidents, and advocates, as well as organizations in strategically important industries.
The U.S. unsealed charges against seven PRC nationals alleged to operate with APT31 under the Hubei State Security Department, accusing them of conspiracy to commit computer intrusions and wire fraud. Prosecutors said the group sent more than 10,000 malicious emails using tracking links, zero-day exploits, malware, and command-and-control infrastructure to compromise government, political, corporate, and civil-society targets worldwide. The coordinated response included U.S. Treasury sanctions against China-linked actors and entities, UK sanctions, and a State Department reward of up to $10 million for information on the accused operators and their network.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
APT31 allegedly targeted email accounts of foreign officials affiliated with the Inter-Parliamentary Alliance on China, including every EU member of IPAC and 43 UK parliamentary accounts, largely belonging to IPAC members or critics of the PRC.
Following Nobel Peace Prize nominations for Hong Kong Umbrella Movement activists, APT31 allegedly targeted Norwegian government officials and a Norwegian managed service provider.
APT31 allegedly began a cyberespionage and transnational-repression campaign operated through the PRC Ministry of State Security's Hubei State Security Department. The campaign allegedly targeted critics of China, government and political personnel, dissidents, and strategically significant businesses.
The UK government and National Cyber Security Centre publicly held China state-affiliated organizations and individuals responsible for malicious cyber activity targeting UK democratic institutions and parliamentarians.
The U.S. Treasury imposed sanctions on two of the charged defendants, while the State Department announced a Reward for Justice offer of up to $10 million for information about the defendants, APT31, and associated entities.
The U.S. Department of Justice unsealed an indictment charging seven PRC nationals alleged to be APT31 members with conspiracy to commit computer intrusions and wire fraud. The indictment alleges the group sent more than 10,000 malicious emails and compromised or potentially compromised victim networks, accounts, devices, and telephone-call records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcegov.uk
Open sourcencsc.gov.uk
Open sourcehome.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.