Reconnaissance
1 technique·derived
Tracking-pixel emails at very high volume for target mapping.
MSS Hubei bureau targeting politicians, election infrastructure, and dissidents — sanctioned by both the U.S. and U.K. in March 2024.
ATTRIBUTED TOChina › Ministry of State Security (MSS) — Hubei State Security Department › Wuhan Xiaoruizhi Science and Technology Company (front company)
APT31 focuses on political intelligence: legislators, election infrastructure, campaign staff, dissidents and their families, and the think tanks that shape policy on China.
Its most distinctive technique is reconnaissance at scale through tracking pixels. Rather than sending malware, operators send tens of thousands of benign-looking emails containing an embedded remote image. When a message is opened, the request to the attacker's server reveals the recipient's IP address, browser, operating system, and device — enough to map a target's location and infrastructure without any code execution and without tripping a single security control. The UK government has stated this technique was used against parliamentarians who had been critical of China.
In March 2024 the U.S. and U.K. acted in coordination. The Department of Justice unsealed an indictment of seven individuals, identifying Wuhan Xiaoruizhi Science and Technology Company as a front for the Hubei State Security Department; the U.S. and U.K. imposed sanctions the same day, with the U.K. citing the group's compromise of the Electoral Commission — which exposed the register data of roughly 40 million voters — and the targeting of parliamentarians.
Down to the named unit where public evidence supports it.
Seven Chinese nationals were indicted by the U.S. Department of Justice in March 2024 for a fourteen-year campaign against U.S. and foreign critics, businesses, and political officials. The indictment identifies Wuhan Xiaoruizhi Science and Technology Company as a front for the Hubei State Security Department, a provincial arm of the MSS. The U.S. Treasury and the U.K. FCDO imposed coordinated sanctions the same day, with the U.K. attributing the Electoral Commission compromise and the targeting of parliamentarians to the group.
Attributing sources
9 designators across 8 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Custom implant used for durable access to compromised networks.
Backdoor using Dropbox for C2, blending exfiltration with normal cloud traffic.
Shared, commodity & living-off-the-land
Remote images embedded in benign emails, revealing recipient IP, browser, and device on open — reconnaissance with no code execution and no detectable payload.
Open-source RAT customised by the group for in-memory operation.
Hijacked home and small-business routers used as C2 relays inside victim geographies.
Post-exploitation framework used for interactive access.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT31 | ||
|---|---|---|---|---|
| CVE-2021-34473KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Aug 2021 | ProxyShell exploitation of Exchange servers, including the intrusion into the UK Electoral Commission's systems.SRCUK Electoral Commission ↗ |
| CVE-2021-26855KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Mar 2021 | ProxyLogon exploited against Exchange servers following the HAFNIUM disclosure.SRCESET ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 May 2018 | OLE2link RTF exploit in phishing against government and policy targets.SRCProofpoint ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Tracking-pixel emails at very high volume for target mapping.
1 technique·derived
Compromised SOHO routers as in-country relays.
2 techniques·derived
Personas impersonating journalists and researchers.
1 technique·derived
Valid Accounts.
2 techniques·derived
Voter registration and membership databases.
2 techniques·derived
Dropbox and other cloud services as C2 channels.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Tracking-pixel emails at very high volume for target mapping
Compromised SOHO routers as in-country relays
Personas impersonating journalists and researchers
Voter registration and membership databases
Dropbox and other cloud services as C2 channels
Compromise of the UK Electoral Commission's systems, exposing register data covering roughly 40 million voters. Attributed by the UK government in March 2024 alongside the targeting of parliamentarians who had been critical of China, and met with coordinated UK and U.S. sanctions.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.