ZIRCONIUM
Zirconium is a China-linked threat actor referenced in the content under multiple aliases including APT31, Bronze Vinewood, Chameleon, Judgement Panda, Judgment Panda, Red Keres, TA412, Violet Typhoon, and WebFans. The content indicates this actor is associated with PRC-sponsored activity and is assessed by Mandiant as one of the PRC-linked groups most likely to target organizations and individuals related to the 2024 Paris Olympics, particularly for espionage-oriented activity such as spearphishing, credential harvesting, and intelligence collection. The content also states that APT31 exploited CVE-2025-53770 against internet-connected SharePoint servers to deploy web shells and obtain initial access. Additional ATT&CK-style procedure references in the content attribute to ZIRCONIUM the use of exploitation for privilege escalation (T1068), multi-hop proxy (T1090.003), AES256 with a SHA1-derived key to decrypt exploit code, capturing the username on a compromised host for C2 registration, and enumerating proxy settings in the target environment. One source in the content also lists Zirconium among threat actors identified in malvertising-related activity.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
Associated vulnerabilities
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
CVE-2025–53770 is a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 9.8. At the time of discovery, sustained exploitation attempts were observed against on premise SharePoint installations worldwide. This vulnerability is known to have been exploited by China based nation state threat actor groups APT27 and APT31, and by another China based ransomware gang Storm 2603, targeting internet connected SharePoint servers to deploy web shells and obtain initial access.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
Microsoft has not confirmed exploitation of CVE-2025-53771; however, CISA assesses exploitation is likely because it can be chained with CVE-2025-53770 to bypass previously disclosed vulnerabilities CVE-2025-49704 and CVE-2025-49706.
ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.
2 more CVEs tied to this actor tracked in Mallory.
Observables
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as using Tailscale to quietly tunnel out of Russian IT firms during 2024 and 2025.
Referenced as a threat actor associated with the MITRE ATT&CK technique T1090.003 (Multi-hop Proxy) in the detection annotation for access to anonymizer services.
Exploited SharePoint vulnerabilities to steal intellectual property.
Named threat actor referenced in retrospective threat reporting.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.