Threat actors
APT31
aptCNvia MISP
2 CVEs attributed
Aliases8
BRONZE VINEWOODJUDGMENT PANDARed keresTA412TIDE CASTLEViolet TyphoonZIRCONIUMZirconium
FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competetive in its field. Based on available data (April 2016), FireEye assesses that APT31 conducts network operations at the behest of the Chinese Government. Also according to Crowdstrike, this adversary is suspected of continuing to target upstream providers (e.g., law firms and managed service providers) to support additional intrusions against high-profile assets. In 2018, CrowdStrike observed this adversary using spear-phishing, URL “web bugs” and scheduled tasks to automate credential harvesting.
Attributed CVEs2
| CVE | Description | Severity | EPSS | Flags | Modified |
|---|---|---|---|---|---|
| CVE-2026-85046 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | HIGH8.8 | 1.46%p72 | KEVPoC | 2026-09-08 |
| CVE-2026-85880 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. | HIGH7.8 | 0.57%p46 | KEV | 2026-09-17 |