G0128: ZIRCONIUM
Security context for executives and security teams
G0128: ZIRCONIUM describes [ZIRCONIUM](https://attack.mitre.org/groups/G0128) is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.(Citation: Microsoft Targeting Elections September 2020)(Citation: Check Point APT31 February 2021)
Executive priority
G0128: ZIRCONIUM is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0128: ZIRCONIUM by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0128: ZIRCONIUM appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
ZIRCONIUM
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1082 | System Information Discovery | ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1598 | Phishing for Information | ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails.CitationGoogle Election Threats October 2020 |
| Enterprise | T1012 | Query Registry | ZIRCONIUM has used a tool to query the Registry for proxy settings.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1665 | Hide Infrastructure | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to obfuscate the origin of C2 traffic.CitationORB Mandiant |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1583.006 | Web ServicesSub-technique | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails.CitationGoogle Election Threats October 2020CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1584.008 | Network DevicesSub-technique | |
| Enterprise | T1555.003 | Credentials from Web BrowsersSub-technique | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1059.006 | PythonSub-technique | ZIRCONIUM has used Python-based implants to interact with compromised hosts.CitationGoogle Election Threats October 2020CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | ZIRCONIUM has created a Registry Run key named |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | ZIRCONIUM has used AES encrypted communications in C2.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1124 | System Time Discovery | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1598.003 | Spearphishing LinkSub-technique | |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | |
| Enterprise | T1583.001 | DomainsSub-technique | |
| Enterprise | T1033 | System Owner/User Discovery | ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1090.003 | Multi-hop ProxySub-technique | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.CitationORB Mandiant |
| Enterprise | T1041 | Exfiltration Over C2 Channel | ZIRCONIUM has exfiltrated files via the Dropbox API C2.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1036 | Masquerading | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware.CitationGoogle Election Threats October 2020CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | ZIRCONIUM has exfiltrated stolen data to Dropbox.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1027.002 | Software PackingSub-technique | |
| Enterprise | T1204.001 | Malicious LinkSub-technique | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware.CitationGoogle Election Threats October 2020CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | ZIRCONIUM has created a run key named |
| Enterprise | T1068 | Exploitation for Privilege Escalation | |
| Enterprise | T1218.007 | MsiexecSub-technique | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1105 | Ingress Tool Transfer | ZIRCONIUM has used tools to download malicious files to compromised hosts.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1016 | System Network Configuration Discovery | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.CitationZscaler APT31 Covid-19 October 2020 |
| Enterprise | T1102.002 | Bidirectional CommunicationSub-technique | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands.CitationGoogle Election Threats October 2020CitationZscaler APT31 Covid-19 October 2020 |
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.3 | Current bundle | 10c449799d71… | ||
| 19.1 | 2.3 | Older bundle | 2d23caddc21c… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Microsoft Targeting Elections September 2020
Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.
Open source URL - [2]Check Point APT31 February 2021
Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021.
Open source URL - [3]APT31
(Citation: Check Point APT31 February 2021)
- [4]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [5]Violet Typhoon
(Citation: Microsoft Threat Actor Naming July 2023)
- [6]mitre-attackG0128Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
