ZIRCONIUM
[ZIRCONIUM](https://attack.mitre.org/groups/G0128) is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)
Properties
- stix_id
- intrusion-set--4283ae19-69c7-4347-a35e-b56f08eb660b
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (29)
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system ove
Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web bro
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications chan
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow fo
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversar
Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished by identifying an
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to cl
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Schedu
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masqueradin
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is t
Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last p
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) rou
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to tr
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contai
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run key
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specifi
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections p
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through info
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is activel
An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such a
Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the prima
Explore this actor's full graph with Ninja Signal