Overview 25 indicators
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.
| domain | 24 | G0128-domain.txt |
| ipv4 | 1 | G0128.json |
Techniques 29 ATT&CK
Open in ATT&CK Navigator → or download the layer (29 techniques, layer 4.5)
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1027.002 Software Packing
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1036.004 Masquerade Task or Service
- T1041 Exfiltration Over C2 Channel
- T1059.003 Windows Command Shell
- T1059.006 Python
- T1068 Exploitation for Privilege Escalation
- T1082 System Information Discovery
- T1090.003 Multi-hop Proxy
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1124 System Time Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1204.001 Malicious Link
- T1218.007 Msiexec
- T1547.001 Registry Run Keys / Startup Folder
- T1555.003 Credentials from Web Browsers
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1573.001 Symmetric Cryptography
- T1583.001 Domains
- T1583.006 Web Services
- T1584.008 Network Devices
- T1598 Phishing for Information
- T1598.003 Spearphishing Link
- T1665 Hide Infrastructure
Principal sources 10 reports
Ranked by how many of this actor's indicators each report brought in.
- 12ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige…
- 12otx.alienvault.com/pulse/610a40dee36aae4fcd35e9cf
- 12virustotal.com/gui/file/33f136069d7c3a030b2e0738a5ee80…
- 12virustotal.com/gui/file/efdbb19fb65bcf5c4a8feb3eab7846…
- 9twitter.com/h2jazi/status/1519769353297747970
- 9virustotal.com/gui/ip-address/31.192.107.152/relations
- 9virustotal.com/gui/file/c4343d5a53495095cf0d44c308c2bb…
- 2cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-013.pdf
Timeline 25 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige…
yandexpro.net -
twitter.com/h2jazi/status/1519769353297747970 · virustotal.com/gui/ip-address/31.192.107.152/relations · virustotal.com/gui/file/c4343d5a53495095cf0d44c308c2bb…
cdn.microsoft-official.com intranet-rsnet.com office.microsoft-products.com offline-microsoft.com p1.offline-microsoft.com portal.intranet-rsnet.com portal.super-encrypt.com super-encrypt.com -
cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-013.pdf
api.last-key.com last-key.com -
ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige… · otx.alienvault.com/pulse/610a40dee36aae4fcd35e9cf · virustotal.com/gui/file/33f136069d7c3a030b2e0738a5ee80… · virustotal.com/gui/file/efdbb19fb65bcf5c4a8feb3eab7846…
domain api.flushcdn.com domain api.hostupoeui.com domain be-government.com domain const.be-government.com domain drmtake.tk domain edgecloudc.com domain flushcdn.com domain gitcloudcache.com domain hostupoeui.com domain inst.rsnet-devel.com domain rsnet-devel.com ipv4 20.11.11.67:443 -
secureworks.com/research/bronz-vinewood-uses-hanaloader…
wshnews.com -
twitter.com/h2jazi/status/1519769353297747970 · virustotal.com/gui/ip-address/31.192.107.152/relations · virustotal.com/gui/file/c4343d5a53495095cf0d44c308c2bb…
microsoft-products.com
Further reading 14
- attack.mitre.org/groups/G0128
- blogs.microsoft.com/on-the-issues/2020/09/10/cyberattacks-u…
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- research.checkpoint.com/2021/the-story-of-jian
- twitter.com/h2jazi/status/1519769353297747970
- virustotal.com/gui/file/33f136069d7c3a030b2e0738a5ee80…
- cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-013.pdf
- ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige…
- virustotal.com/gui/ip-address/31.192.107.152/relations
- virustotal.com/gui/file/c4343d5a53495095cf0d44c308c2bb…
- ptsecurity.com/ww-en/analytics/pt-esc-threat-intellige…
- otx.alienvault.com/pulse/610a40dee36aae4fcd35e9cf
- secureworks.com/research/bronz-vinewood-uses-hanaloader…
- virustotal.com/gui/file/efdbb19fb65bcf5c4a8feb3eab7846…