Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group] · confidence: low · affected_sectors: [] · au_impact: false

ZIRCONIUM

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.

Attribute Detail
ATT&CK ID G0128
Aliases APT31, Violet Typhoon
Attribution Not stated by MITRE ATT&CK
Class unknown
Active since 2017 (per ATT&CK description)
ATT&CK entry created 2021-03-24
Techniques mapped 29

Attribution — as claimed

Not attributed in ATT&CK — treat any naming as unconfirmed.

Known TTPs

Technique Name
T1012 Query Registry
T1016 System Network Configuration Discovery
T1027.002 Software Packing
T1033 System Owner/User Discovery
T1036 Masquerading
T1036.004 Masquerade Task or Service
T1041 Exfiltration Over C2 Channel
T1059.003 Windows Command Shell
T1059.006 Python
T1068 Exploitation for Privilege Escalation
T1082 System Information Discovery
T1090.003 Multi-hop Proxy

(First 12 of 29 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — similarly attributed-linked actor, same attribution class
  • Apt28 — similarly attributed-linked actor, same attribution class
  • Apt29 — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0128 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.