🌐ZIRCONIUM
🌐 ZIRCONIUM is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 29 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
29Techniques
0IOCs
About this actor (MITRE)
[ZIRCONIUM](https://attack.mitre.org/groups/G0128) is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)
Known aliases
ZIRCONIUMAPT31Violet Typhoon
Top techniques
All other tracked techniques
T1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.004 · Masquerade Task or ServiceT1041 · Exfiltration Over C2 ChannelT1059.003 · Windows Command ShellT1059.006 · PythonT1068 · Exploitation for Privilege EscalationT1082 · System Information DiscoveryT1090.003 · Multi-hop ProxyT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1124 · System Time DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1204.001 · Malicious LinkT1218.007 · MsiexecT1547.001 · Registry Run Keys / Startup FolderT1555.003 · Credentials from Web BrowsersT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1573.001 · Symmetric CryptographyT1583.001 · DomainsT1583.006 · Web ServicesT1584.008 · Network DevicesT1598 · Phishing for InformationT1598.003 · Spearphishing LinkT1665 · Hide Infrastructure