APT31 (also known as Zirconium, Judgment Panda) threat actor
APT31 is a Chinese state-sponsored cyber espionage group that gathers intelligence in support of the interests of the People's Republic of China (PRC). Active for over a decade, it is best known for targeted spearphishing against governments, politicians, critical infrastructure, and businesses, and for stealing both political intelligence and commercial trade secrets. In March 2024, the United States and United Kingdom formally linked the group to China's Ministry of State Security (MSS), sanctioning a front company and indicting or sanctioning several individuals. The actor is tracked under several names, most commonly Zirconium, Judgment Panda, and Violet Typhoon, and MITRE ATT&CK catalogs it as G0128. APT31's targeting follows PRC strategic priorities rather than any single industry, and its tradecraft leans on legitimate services and compromised home and office routers to hide its activity. This page covers the group's attribution and aliases, who it targets, how it operates, its notable campaigns, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
Key takeaways
- APT31 is a Chinese state-sponsored espionage group linked to the Ministry of State Security, active for more than a decade.
- It was formally attributed in 2024. The US and UK sanctioned an MSS front company and named individuals, and the US indicted seven people tied to the group.
- It has several names. Zirconium, Judgment Panda, and Violet Typhoon all refer to the same actor, tracked by MITRE as G0128.
- Its targets are politically and economically strategic, including governments, politicians, election bodies, dissidents, journalists, critical infrastructure, and companies holding valuable intellectual property.
- It hides in legitimate services and home routers. APT31 abuses services like GitHub and Dropbox and builds relay networks from compromised routers to disguise its traffic.
Attribution and aliases
APT31 is attributed to the Chinese state, and specifically to the MSS. In March 2024, the United States unsealed an indictment charging seven Chinese nationals connected to the group and, together with the United Kingdom, imposed sanctions on Wuhan Xiaoruizhi Science and Technology Company (Wuhan XRZ), described as an MSS front company operating under the Hubei State Security Department, along with individuals linked to it. This built on earlier statements: in July 2021 the UK and the European Union publicly held the Chinese state responsible for APT31 activity. The individuals named in the indictment are subject to charges and sanctions rather than convictions, and are presumed innocent unless proven guilty in court.
Because several vendors have tracked the group independently, it carries a handful of names. The most common are below:
- APT31
- Zirconium
- Violet Typhoon
- Judgment Panda
- Red Keres
- Bronze Vinewood
- G0128
They all point to the same actor. Some reporting has suggested the group operates as MSS contractors or has links to elements of China's military, and as with most attributions the assessments are expressed with degrees of confidence, though the 2024 government actions place the state link on a firm footing.
Who APT31 targets
APT31's targeting is defined by the PRC's political and economic interests rather than by a single sector. Its recurring targets include:
- Government and political figures, including officials, lawmakers, candidates, and campaign staff. The group targeted individuals associated with the 2020 US presidential election.
- Democratic institutions, including a compromise of the UK Electoral Commission between 2021 and 2022 and reconnaissance against UK parliamentarians.
- Dissidents, journalists, and academics, consistent with the transnational repression of critics of the Chinese government.
- Critical infrastructure and defense, including US energy-sector and military-affiliated targets.
- Companies with valuable intellectual property, reflecting an economic-espionage and trade-secret-theft dimension alongside the political one.
Geographically the group has operated across the United States, Europe, and beyond, including a 2021 campaign against numerous French entities documented by the French national cybersecurity agency ANSSI. According to the 2024 indictment, the group sent more than 10,000 malicious emails and affected thousands of targets across multiple continents over roughly fourteen years.
How APT31 operates
APT31's tradecraft is often not technically advanced, but it is effective, relying heavily on legitimate services and disguised infrastructure to evade defenses. Its activity maps onto the MITRE ATT&CK framework.
Two traits stand out. First, the group's heavy use of legitimate services, GitHub to host implants and the Dropbox API for command-and-control, lets its traffic blend into normal activity and slip past controls that would block unfamiliar infrastructure. Second, APT31 is one of the relatively few actors known to build its operational infrastructure from compromised small-office and home-office (SOHO) routers, creating relay networks that obscure the true origin of its attacks. It has also used stolen exploit code, including the so-called Jian tool derived from a leaked zero-day, showing an ability to repurpose advanced capabilities when available.
Notable campaigns and activity
Across its history, APT31 has been tied to a series of espionage operations:
- 2020 US election targeting. The group targeted individuals associated with a US presidential campaign with credential-phishing activity, reported publicly by major technology vendors.
- 2021 France campaign. ANSSI published indicators of a campaign against numerous French entities, drawing on the group's router-based infrastructure.
- UK Electoral Commission compromise (2021-2022). UK authorities attributed to the group the compromise of electoral registers holding data on tens of millions of voters, alongside reconnaissance against parliamentarians.
- 2024 indictment and sanctions. The US and UK actions named an MSS front company and individuals, detailing a global operation spanning roughly fourteen years against political, government, and commercial targets.
How to defend against APT31
Because APT31 relies on phishing, legitimate services, and disguised infrastructure rather than noisy exploits, defense combines identity protection with behavioral detection:
- Harden against phishing. Strong email filtering, user awareness, and phishing-resistant authentication reduce the group's main route to initial access, which is a credential-phishing link.
- Watch legitimate services for abuse. Because command-and-control hides in services such as GitHub and Dropbox, monitoring for anomalous use of legitimate cloud services is more effective than blocklists alone.
- Account for relay infrastructure. Since the group proxies traffic through compromised home and office routers, connections from residential or unexpected networks should not be treated as inherently trustworthy, and edge devices should be patched and monitored.
- Hunt for persistence and credential theft. Monitor for registry-based persistence, browser-credential access, and long-lived mailbox or cloud-account access, which are the behaviors that reveal a long-dwell intrusion.
- Use threat intelligence. Tracking APT31's known infrastructure heuristics, tooling, and current campaigns helps teams recognize its activity in context and prioritize the sectors it targets.
Sekoia's research on APT31
Sekoia's TDR team has investigated APT31's infrastructure directly. Following publications by Germany's BfV, McAfee, and France's ANSSI in 2021, TDR analyzed the group's operational relay networks and found that many of its command-and-control indicators pointed to compromised SOHO routers, initially a cluster of one router brand before the group shifted to others to avoid being tracked. From there, TDR developed heuristics, based on domain-naming patterns, DNS configuration and providers, and the characteristics of the compromised appliances, to illuminate parts of the group's infrastructure over time, and identified implants including Cobalt Strike beacons and a backdoor built on the Tiny SHell tool. This kind of first-hand infrastructure tracking is what turns a named actor into something a defender can actually hunt for, and it is published on the Sekoia blog with indicators shared openly.
Expert insight: Hiding in plain sight
APT31 is a reminder that a state actor does not need cutting-edge malware to be effective. Its strength is camouflage: implants hosted on GitHub, command-and-control running through the Dropbox API, and traffic relayed through ordinary home routers so that an intrusion looks like everyday internet activity. Each of those choices is designed to defeat controls that decide what is malicious based on where traffic comes from or what service it uses. A connection to Dropbox or a login from a residential address is unremarkable on its own, which is exactly why the technique works.
This is where a CTI-led approach earns its place, and where Sekoia's own work on APT31 is instructive. Sekoia is a European cybersecurity vendor whose in-house TDR team tracks China-nexus actors such as APT31, including the infrastructure heuristics that distinguish its relay networks, and that intelligence feeds the platform. Rather than treating a single cloud connection or router-sourced login as isolated noise, Sekoia's AI SOC platform correlates signals across endpoint, network, and cloud and maps them to the MITRE ATT&CK framework, so that phishing leading to credential theft and cloud-based command-and-control can be recognized as one intrusion. The infrastructure tracking Sekoia published on APT31 is an example of turning first-hand intelligence into detection that holds up even when an actor hides in legitimate services.
The practical takeaway for defenders is that an actor this camouflaged is caught through context and intelligence, not through any single alert. Prevention such as phishing-resistant authentication and edge-device patching is essential and will stop many attempts, but the intrusions that succeed are the ones that look ordinary, and those surface only when identity, endpoint, network, and cloud telemetry are read together against current intelligence on the actor. As a European vendor with a data-sovereignty posture, Sekoia is well placed to support the government and critical-infrastructure organizations that APT31 targets.