created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group] · confidence: low · affected_sectors: [] · au_impact: false
ZIRCONIUM
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0128 |
| Aliases | APT31, Violet Typhoon |
| Attribution | Not stated by MITRE ATT&CK |
| Class | unknown |
| Active since | 2017 (per ATT&CK description) |
| ATT&CK entry created | 2021-03-24 |
| Techniques mapped | 29 |
Attribution — as claimed
Not attributed in ATT&CK — treat any naming as unconfirmed.
Known TTPs
| Technique | Name |
|---|---|
T1012 |
Query Registry |
T1016 |
System Network Configuration Discovery |
T1027.002 |
Software Packing |
T1033 |
System Owner/User Discovery |
T1036 |
Masquerading |
T1036.004 |
Masquerade Task or Service |
T1041 |
Exfiltration Over C2 Channel |
T1059.003 |
Windows Command Shell |
T1059.006 |
Python |
T1068 |
Exploitation for Privilege Escalation |
T1082 |
System Information Discovery |
T1090.003 |
Multi-hop Proxy |
(First 12 of 29 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — similarly attributed-linked actor, same attribution class
- Apt28 — similarly attributed-linked actor, same attribution class
- Apt29 — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0128 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.