news.mlab.sh
Threat intelligence
Threat actor

APT 31

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2016-01-01 00:00:00
Motivation
Information theft and espionage
TLP
WHITE

FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competetive in its field. Based on available data (April 2016), FireEye assesses that APT31 conducts network operations at the behest of the Chinese Government. Also see Hafnium.

Also known as

APT 31APT31Bronze VinewoodG0128Judgment PandaRed KeresRedBravoTA412Violet TyphoonZirconium

Vulnerabilities exploited

MITRE ATT&CK techniques

T1105 Ingress Tool TransferT1665 Hide InfrastructureT1012 Query RegistryT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1082 System Information DiscoveryT1124 System Time DiscoveryT1041 Exfiltration Over C2 ChannelT1068 Exploitation for Privilege EscalationT1598 Phishing for InformationT1036 MasqueradingT1140 Deobfuscate/Decode Files or Information

Coverage 5