- Target Sectors
- Government, Military, Diplomatic, Political, Electoral, International Affairs, Academia, Think Tanks, Journalism, Defense Industrial Base, Information Technology, Telecommunications, Energy, Managed Service Providers, Financial, Consulting, Legal, Research
- Associated Malware
- RAWDOOR, Trochilus, EvilOSX, DropDoor, DropCat, CobaltStrike, FourteenHi, MeatBall, CloudSorcerer, Python implants, Web shells
Overview
ZIRCONIUM, also known as APT31 or Violet Typhoon (MITRE ATT&CK ID: G0128), is a sophisticated and highly active cyber espionage group operating on behalf of the Chinese Ministry of State Security (MSS). Specifically, the group is attributed to the Hubei State Security Department, based in Wuhan, China, and has been active since at least 2010. ZIRCONIUM has used front companies, such as “Wuhan Xiaoruizhi Science and Technology Company” (Wuhan XRZ) and “Wuhan Liuhe,” to mask its cyber operations.
The primary motivation behind ZIRCONIUM’s activities is cyber espionage and intelligence gathering to advance China’s strategic and geopolitical objectives. This includes repressing critics of the Chinese regime, compromising governmental institutions, and stealing valuable intellectual property and trade secrets from companies vital to national economic interests.
ZIRCONIUM’s targeting is broad and global, encompassing a wide array of high-value entities across the United States, European Union (including France, Germany, the United Kingdom, Finland, and the Czech Republic), Asia-Pacific regions (such as Japan, South Korea, and India), and even Russia. Their typical targets include government agencies, diplomatic missions, military organizations, political figures, electoral bodies, and campaign staff. The group also extensively targets individuals within the international affairs community, foreign policy experts, academics, journalists, and pro-democracy activists, particularly those critical of the Chinese government. Economically, ZIRCONIUM focuses on critical infrastructure sectors such as the Defense Industrial Base, information technology, telecommunications (including 5G equipment providers), and energy companies. They often gain initial access by targeting managed service providers (MSPs), law firms, or even the family members and spouses of high-ranking officials to breach less-secured home networks.
Tactics & Techniques
ZIRCONIUM employs a sophisticated and evolving set of tactics, techniques, and procedures (TTPs) designed for long-term infiltration and covert data exfiltration. Initial access is predominantly achieved through highly targeted spearphishing emails. These emails are frequently crafted to appear legitimate, often impersonating prominent journalists or news outlets and embedding legitimate news article excerpts along with hidden tracking links. Clicking these links allows ZIRCONIUM to gather preliminary reconnaissance information, such as the victim’s device type and public IP address, which is then used to tailor more direct and sophisticated hacking attempts.
The group is known to exploit zero-day vulnerabilities, as seen with CVE-2017-0005 for local privilege escalation and more recently with a series of SharePoint vulnerabilities (CVE-2025-49706, CVE-2025-49704, CVE-2025-53770, and CVE-2025-53771). For persistence, ZIRCONIUM establishes Registry Run keys, sometimes disguised as legitimate entries like “Dropbox Update Setup,” and employs DLL hijacking.
To evade detection, ZIRCONIUM utilizes compromised small office/home office (SOHO) routers and Internet of Things (IoT) devices as operational relay boxes (ORBs) or proxy networks, obfuscating the origin of their command and control (C2) traffic. They also engage in “living off the land” techniques, using built-in operating system tools to blend in with normal network activity and avoid triggering endpoint detection and response (EDR) systems. Malware payloads are often encrypted, injected into memory, and sometimes spoof legitimate applications or use altered file extensions. For C2 and data exfiltration, ZIRCONIUM frequently leverages popular legitimate cloud services like Dropbox, GitHub, and Yandex Cloud, making their malicious traffic difficult to distinguish from benign network activity. They also use AES encrypted communications for C2. Information discovery techniques include querying the Registry for proxy settings and collecting system details such as processor architecture, usernames, and system time.
Notable Campaigns
ZIRCONIUM has been linked to numerous significant cyber espionage campaigns globally. In 2018, the group engaged in a large-scale email campaign, sending over 10,000 tracking emails to collect initial intelligence. Following the nomination of Hong Kong’s Umbrella Movement activists for the Nobel Peace Prize in 2019, ZIRCONIUM intensified its targeting of these activists, as well as journalists and Norwegian government officials.
Leading up to the 2020 US presidential election, ZIRCONIUM actively targeted individuals associated with the campaigns, including staff from both major political parties. Between late 2020 and early 2021, the group was responsible for a cyberattack against the Finnish parliament. In 2021, they conducted reconnaissance activity against British parliamentarians, particularly those vocal in their criticism of China. The group was also publicly linked to global compromises of Microsoft Exchange servers in 2021, and the compromise of the UK Electoral Commission between 2021 and 2022.
In a less common move, ZIRCONIUM launched a campaign against Russian media and energy companies in 2022, leveraging Yandex Cloud for command and control infrastructure. More recently, in July 2023, the group targeted industrial organizations in Eastern Europe, focusing on intellectual property theft, including data from air-gapped systems, utilizing sophisticated DLL hijacking techniques and a variety of implants. In March 2024, the group was observed targeting US organizations within critical infrastructure sectors, including the Defense Industrial Base, information technology, and energy. Also in March 2024, the US Department of Justice unsealed an indictment against seven individuals associated with APT31, accompanied by US Treasury sanctions against Wuhan XRZ and two specific hackers. As recently as May 2025, the Czech Ministry of Foreign Affairs was attacked by ZIRCONIUM, compromising an unclassified network considered critical national infrastructure.
Associated Malware & Tools
ZIRCONIUM possesses a diverse arsenal of malware and tools, often blending custom-developed implants with commercially available or cracked software. Notable custom malware families include RAWDOOR, Trochilus, EvilOSX, and DropDoor/DropCat. They have also been observed using cracked versions of CobaltStrike for post-exploitation activities. For initial access and persistent remote access, ZIRCONIUM uses specific implants such as FourteenHi and MeatBall, with the latter offering extensive remote access capabilities like process listing, screenshot capture, and remote shell access. Python-based implants are also part of their toolkit for interacting with compromised hosts.
In the EastWind campaign targeting Russian entities, an updated CloudSorcerer backdoor was detected. The group also deploys web shells, such as “spinstall0.aspx” and “spinstall.aspx,” to maintain access to compromised SharePoint servers. Beyond bespoke malware, ZIRCONIUM heavily abuses legitimate online services for C2 and data exfiltration, including the Dropbox API, GitHub to host malware, and Yandex Cloud. They have also used a keylogger as part of their operations.
Current Status
ZIRCONIUM remains an active and evolving threat, continuously adapting its TTPs and expanding its malware arsenal. Recent intelligence indicates that the group continues to pose a significant threat to global cybersecurity. In March 2024, the US Department of Justice indicted seven individuals linked to ZIRCONIUM for their extensive cyber operations. Concurrently, the US Department of the Treasury imposed sanctions on Wuhan XRZ and two named individuals for their roles in targeting US critical infrastructure.
Ongoing activity includes targeting US critical infrastructure sectors in March 2024, new CloudSorcerer attacks against Russian government and IT organizations in July 2024, and the exploitation of multiple SharePoint vulnerabilities as recently as July 2025. The attack on the Czech Ministry of Foreign Affairs in May 2025 further highlights their continued targeting of government entities. As of early 2026, there are conflicting assessments regarding the full remediation of some compromised systems, suggesting a credible possibility that ZIRCONIUM retains access in certain environments. This sustained activity underscores ZIRCONIUM’s persistent threat and its integral role in China’s state-sponsored cyber espionage efforts.
Related content
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call