Skip to content
ChinaState-SponsoredActiveMITRE G0128

APT31

MSS Hubei bureau targeting politicians, election infrastructure, and dissidents — sanctioned by both the U.S. and U.K. in March 2024.

ATTRIBUTED TOChina › Ministry of State Security (MSS) — Hubei State Security Department › Wuhan Xiaoruizhi Science and Technology Company (front company)

Open MITRE Navigator layer ↗Download profile JSON
Active
2010–present
Motivation
Espionage, Information Operations
Aliases
9
Exploited CVEs
3
ATT&CK techniques
9
Cited sources
8

Overview

APT31 focuses on political intelligence: legislators, election infrastructure, campaign staff, dissidents and their families, and the think tanks that shape policy on China.

Its most distinctive technique is reconnaissance at scale through tracking pixels. Rather than sending malware, operators send tens of thousands of benign-looking emails containing an embedded remote image. When a message is opened, the request to the attacker's server reveals the recipient's IP address, browser, operating system, and device — enough to map a target's location and infrastructure without any code execution and without tripping a single security control. The UK government has stated this technique was used against parliamentarians who had been critical of China.

In March 2024 the U.S. and U.K. acted in coordination. The Department of Justice unsealed an indictment of seven individuals, identifying Wuhan Xiaoruizhi Science and Technology Company as a front for the Hubei State Security Department; the U.S. and U.K. imposed sanctions the same day, with the U.K. citing the group's compromise of the Electoral Commission — which exposed the register data of roughly 40 million voters — and the targeting of parliamentarians.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS) — Hubei State Security DepartmentWuhan Xiaoruizhi Science and Technology Company (front company)Confirmed

Seven Chinese nationals were indicted by the U.S. Department of Justice in March 2024 for a fourteen-year campaign against U.S. and foreign critics, businesses, and political officials. The indictment identifies Wuhan Xiaoruizhi Science and Technology Company as a front for the Hubei State Security Department, a provincial arm of the MSS. The U.S. Treasury and the U.K. FCDO imposed coordinated sanctions the same day, with the U.K. attributing the Electoral Commission compromise and the targeting of parliamentarians to the group.

Attributing sources

Cross-vendor naming crosswalk

9 designators across 8 organisations.

MITRE ATT&CK

index ↗
  • APT31

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Violet TyphoonFormerly ZIRCONIUM
  • ZIRCONIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Judgment Panda

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT31

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE VINEWOOD

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • RedBravo

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Proofpoint

index ↗
  • TA412

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • APT31 / Hubei State Security Department

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomFinlandNorwayGermanyFranceCzechiaAustraliaNew Zealand

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

RAWDOORbackdoor

Custom implant used for durable access to compromised networks.

DropboxAESbackdoor

Backdoor using Dropbox for C2, blending exfiltration with normal cloud traffic.

Shared, commodity & living-off-the-land

Tracking pixelsutility

Remote images embedded in benign emails, revealing recipient IP, browser, and device on open — reconnaissance with no code execution and no detectable payload.

Trochilusbackdoor

Open-source RAT customised by the group for in-memory operation.

Compromised routersutility

Hijacked home and small-business routers used as C2 relays inside victim geographies.

Cobalt Strikeframework

Post-exploitation framework used for interactive access.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT31
CVE-2021-34473KEVransomware9.81 Aug 2021ProxyShell exploitation of Exchange servers, including the intrusion into the UK Electoral Commission's systems.SRCUK Electoral Commission
CVE-2021-26855KEVransomware9.81 Mar 2021ProxyLogon exploited against Exchange servers following the HAFNIUM disclosure.SRCESET
CVE-2017-0199KEVransomware7.81 May 2018OLE2link RTF exploit in phishing against government and policy targets.SRCProofpoint

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 9 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
9 techniques across 6 tactics · 5 with actor-specific notes

Reconnaissance

1

Resource Development

1

Initial Access

2

Command and Control

2

Campaign timeline

  1. UK Electoral Commission Compromise

    Compromise of the UK Electoral Commission's systems, exposing register data covering roughly 40 million voters. Attributed by the UK government in March 2024 alongside the targeting of parliamentarians who had been critical of China, and met with coordinated UK and U.S. sanctions.

    CVE-2021-34473GovernmentPolitical Organizations

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.