Skip to content

Hide Navigation Hide TOC

APT31 (6bf7e6b6-5917-45a6-9567-f0baba79768c)

FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competetive in its field. Based on available data (April 2016), FireEye assesses that APT31 conducts network operations at the behest of the Chinese Government. Also according to Crowdstrike, this adversary is suspected of continuing to target upstream providers (e.g., law firms and managed service providers) to support additional intrusions against high-profile assets. In 2018, CrowdStrike observed this adversary using spear-phishing, URL “web bugs” and scheduled tasks to automate credential harvesting.

Cluster A Galaxy A Cluster B Galaxy B Level
APT31 (6bf7e6b6-5917-45a6-9567-f0baba79768c) Threat Actor ZIRCONIUM (2d19c573-252b-49d8-8c2e-3b529b91e72d) Microsoft Activity Group actor 1
APT31 (6bf7e6b6-5917-45a6-9567-f0baba79768c) Threat Actor Violet Typhoon (27eb4928-b3e6-5ae1-bbb6-f73bce8d7c69) Microsoft Activity Group actor 1