CN

APT31

High ConfidenceHigh Threat

Zirconium • Judgment Panda • Violet Typhoon • Bronze Vinewood • Red Keres

APT31, also known as Zirconium or Judgment Panda, is a Chinese state-sponsored threat actor associated with the Ministry of State Security. The group specializes in targeting government entities, international affairs organizations, and high-profile individuals including politicians, journalists, and activists. APT31 gained significant attention for targeting the 2020 U.S. presidential election campaigns and conducting extensive operations against European parliaments. Their toolkit includes custom implants and they frequently leverage compromised infrastructure to mask their operations.

Origin: China
Sponsor: MSS (Ministry of State Security)
Active: 2010 - Present
Victims: 200+ organizations
Advanced
Active
EspionagePolitical Intelligence
Risk Assessment
74
Composite Risk Score
High Risk
ARCS Compliance78
Escalation Risk75
Grievance Index72
Infrastructure Impact70
History & Evolution

APT31, also known as Zirconium or Judgment Panda, is a Chinese state-sponsored threat actor associated with the Ministry of State Security. The group specializes in targeting government entities, international affairs organizations, and high-profile individuals including politicians, journalists, and activists. APT31 gained significant attention for targeting the 2020 U.S. presidential election campaigns and conducting extensive operations against European parliaments. Their toolkit includes custom implants and they frequently leverage compromised infrastructure to mask their operations.

Targeting

Target Sectors

GovernmentPolitical OrganizationsTechnologyDefenseInternational Affairs

Target Regions

EuropeUnited StatesAsia Pacific
Attribution & Affiliations

Attributed to MSS (Ministry of State Security) (China). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

APT31 is expected to continue operations targeting Government sectors.

Timeline of Key Events
2010
Major

First observed activity of APT31

2024
Moderate

Continued active operations