APT31 is a Chinese state-linked cyberespionage group active since at least 2016, conducting intelligence collection in support of Chinese government and state-owned enterprise interests. It is also tracked as Zirconium, Violet Typhoon, Judgment Panda or Judgement Panda, Bronze Vinewood, Red Keres, TA412, Chameleon, and WebFans. Its targets include government institutions, political campaign personnel, former government and military personnel, defense and aerospace organizations, NGOs, think tanks, higher education, financial institutions, technology companies, media, healthcare, energy, mining, and commodity-trading organizations. Documented operations include attacks against Finland's parliament, a broad campaign against French entities in 2021, and attacks against Russian media and energy companies in 2022. APT31 obtains initial access through credential phishing, malicious email links and documents, password guessing and spraying, compromised accounts, SQL injection, and exploitation of internet-facing applications. It uses email web beacons to track recipient activity and disguises malicious components as legitimate applications. Observed exploitation includes Fortinet VPN vulnerability CVE-2018-13379, the Exchange ProxyLogon chain, and on-premises SharePoint vulnerabilities associated with ToolShell in 2025. The group also exploits local privilege-escalation vulnerabilities, including CVE-2017-0005, and uses tools such as Juicy Potato to obtain elevated execution privileges. Its post-compromise activity includes browser credential dumping, LSASS memory dumping, account and network discovery, service scanning, lateral movement through RDP and FTP, and tool transfer through SMB. Persistence mechanisms include web shells, scheduled tasks, services, startup entries, and newly created accounts resembling legitimate privileged or service accounts. APT31 employs DLL side-loading, process injection, encrypted payloads, packing, legitimate-service impersonation, security exclusions, firewall modifications, and artifact deletion. Its tooling includes Cobalt Strike, Metasploit, DropboxAES RAT, YaRAT, Stealer0x3401, and the Pakdoor router backdoor. It collects emails, user databases, system information, and sensitive business data, using cloud services, DNS, SMB, and custom protocols for command and control or exfiltration. A distinctive operational feature is its mesh of compromised small-office and home-office routers, managed through Pakdoor and used for reconnaissance, scanning, and command-and-control anonymization. In 2026, operations tracked as TA412 used fake conference invitations against US nonprofit organizations, mining companies, and commodity traders to direct recipients to BlueMoon Exploit Kit landing pages. These attacks delivered GemStone, a malicious browser extension masquerading as an AI browsing companion that collects keystrokes, cookies, browser storage, and screenshots.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
66 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
41 malware families attributed to this actor across reporting.
36 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
The first exploit targets CVE-2026-85046 in V8's optimizing compilers. When an array's element type changes during sorting, the optimized code can treat a value as the wrong type.
That DLL checks the Windows build again, then tries CVE-2026-85880. The exploit uses the ALPC communication and WNF notification mechanisms to gain kernel read/write access.
The next exploit, CVE-2026-87491, escapes the V8 sandbox. BlueMoon corrupts WebAssembly metadata and replaces compiled function code with the p1 shellcode.
Once these cryptographic secrets are retrieved, they can craft fully valid and signed __VIEWSTATE payloads. | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
CVE-2025-49704 (a code injection/remote code execution, or RCE, vulnerability). When chained together, these vulnerabilities allowed authorized attackers to gain remote code execution and access or alter sensitive information.
9 more CVEs tied to this actor tracked in Mallory.
403 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted an espionage-focused campaign using conference-themed spearphishing and the BlueMoon exploit chain to install GemStone, a malicious browser extension that collects keystrokes, cookies, browser storage, and screenshots.
A Chinese state-sponsored group mentioned as having exploited ToolShell zero-days before public disclosure; it is background context rather than the focus of this report.
Listed in the detection's technique annotations; the content does not attribute ShieldCrash exploitation to this group.
Mentioned as a comparison because its SUPERSTOMP tool uses a Chrome Secure Preferences integrity bypass also observed in LunexStealer. The researchers downgraded the proposed connection after finding independent implementations across unrelated operations; the shared technique does not establish APT31 involvement in this campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.