ZIRCONIUM
Also reported as Violet Typhoon, APT31, Zirconium, TA412, JUDGMENT PANDA and 10 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1059.001 4 reports reports only
- T1005 3 reports reports only
- T1033 3 reports in ATT&CK
- T1059.003 3 reports in ATT&CK
- T1082 3 reports in ATT&CK
- T1132.001 3 reports reports only
- T1140 3 reports in ATT&CK
- T1190 3 reports reports only
- T1204.002 3 reports reports only
- T1543.003 3 reports reports only
Show all 72 techniques Show fewer
- T1547.001 3 reports in ATT&CK
- T1003.001 2 reports reports only
- T1027 2 reports reports only
- T1036.005 2 reports reports only
- T1047 2 reports reports only
- T1053.005 2 reports reports only
- T1057 2 reports reports only
- T1068 2 reports in ATT&CK
- T1083 2 reports reports only
- T1090 2 reports reports only
- T1112 2 reports reports only
- T1119 2 reports reports only
- T1484.001 2 reports reports only
- T1486 2 reports reports only
- T1505.003 2 reports reports only
- T1505.004 2 reports reports only
- T1566.001 2 reports reports only
- T1566.002 2 reports in ATT&CK
- T1569.002 2 reports reports only
- T1570 2 reports reports only
- T1573.001 2 reports in ATT&CK
- T1620 2 reports reports only
- T1001.003 1 report reports only
- T1012 1 report in ATT&CK
- T1014 1 report reports only
- T1027.009 1 report reports only
- T1036.007 1 report reports only
- T1041 1 report in ATT&CK
- T1055 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1071.001 1 report reports only
- T1090.001 1 report reports only
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1106 1 report reports only
- T1124 1 report in ATT&CK
- T1129 1 report reports only
- T1189 1 report reports only
- T1195.001 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report in ATT&CK
- T1218.014 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1518.001 1 report reports only
- T1553.002 1 report reports only
- T1555.003 1 report in ATT&CK
- T1564.010 1 report reports only
- T1567.002 1 report in ATT&CK
- T1572 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report reports only
- T1583.001 1 report in ATT&CK
- T1583.003 1 report reports only
- T1587.001 1 report reports only
- T1588.002 1 report reports only
- T1590 1 report reports only
- T1595 1 report reports only
- T1608.001 1 report reports only
- T1622 1 report reports only
- T1627.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 13 techniques Show fewer
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2008-5353
- CVE-2009-0556 KEV
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
Show all 170 CVEs Show fewer
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-0611 KEV
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-3128
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3894
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0005 KEV
- CVE-2017-0038
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-15944 KEV
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-7269 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-16098
- CVE-2019-16759 KEV
- CVE-2019-17100
- CVE-2019-19781 KEV ransomware
- CVE-2019-9489
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-2551 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-21551 KEV
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26352 KEV ransomware
- CVE-2022-27518 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-20198 KEV
- CVE-2023-20273 KEV
- CVE-2023-20867 KEV
- CVE-2023-26360 KEV
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-3519 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-7101 KEV
- CVE-2023-7102
- CVE-2024-0012 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
Show all 265 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor China Chopper - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What to Expect When You’re Electing- Preparing for Cyber Threats to the 2022 U.S. Midterm Elections
-
Flying in the clouds- APT31 renews its attacks on Russian companies through cloud storage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Flying in the clouds- APT31 renews its attacks on Russian companies through cloud storage
-
Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Above the Fold and in Your Inbox- Tracing State-Aligned Activity Targeting Journalists, Media
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
-
A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive into DoubleFeature, Equation Group’s Post-Exploitation Dashboard
-
A Deep Dive Into SoWaT- APT31’s Multifunctional Router Implant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Deep Dive Into SoWaT- APT31’s Multifunctional Router Implant
-
Walking on APT31 infrastructure footprints
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Walking on APT31 infrastructure footprints
-
Profiling hackers using the Malvertising Attack Matrix by Confiant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling hackers using the Malvertising Attack Matrix by Confiant
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
APT31 new dropper. Target destinations_ Mongolia, Russia, the U.S., and elsewhere
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT31 new dropper. Target destinations_ Mongolia, Russia, the U.S., and elsewhere
-
INDICATEURS DE COMPROMISSION DU CERT-FR
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor INDICATEURS DE COMPROMISSION DU CERT-FR
-
UK and allies hold Chinese state responsible for a pervasive pattern of hacking
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UK and allies hold Chinese state responsible for a pervasive pattern of hacking
-
For the first time, PST says that China (APT31) is behind a computer attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor For the first time, PST says that China (APT31) is behind a computer attack
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The investigation of the computer network operation (by APT31) against public administration offices is closed
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
Supo identified the cyber espionage operation against the parliament as APT31
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Supo identified the cyber espionage operation against the parliament as APT31
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Eduskunnan tietojärjestelmiin kohdistuneen tietomurron tutkinnassa selvitetään yhteyttä APT31-toimijaan
-
research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
-
The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
APT-31 leverages COVID-19 vaccine theme and abuses legitimate online services
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-31 leverages COVID-19 vaccine theme and abuses legitimate online services
-
How we're tackling evolving online threats
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How we're tackling evolving online threats
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
New cyberattacks targeting U.S. elections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New cyberattacks targeting U.S. elections
-
BRONZE VINEWOOD Targets Supply Chains _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains _ Secureworks
-
BRONZE VINEWOOD Targets Supply Chains
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BRONZE VINEWOOD Targets Supply Chains
-
DropboxAES Remote Access Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DropboxAES Remote Access Trojan
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
APT Groups Moving Down the Supply Chain
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Groups Moving Down the Supply Chain
-
Operation Red Signature Targets South Korean Companies
The original link failed its last check. Original publisher Detailsfor Operation Red Signature Targets South Korean Companies
-
Uncovering 2017’s Largest Malvertising Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering 2017’s Largest Malvertising Operation
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
Newest first. Details opens the report in Explore.