ATT&CKGroupsZIRCONIUM

ZIRCONIUM

G0128

Threat group.View on attack.mitre.org

About this group

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1012
Query Registry

ZIRCONIUM has used a tool to query the Registry for proxy settings.

T1016
System Network Configuration Discovery

ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.

T1027.002
Software Packing

ZIRCONIUM has used multi-stage packers for exploit code.

T1033
System Owner/User Discovery

ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2.

T1036
Masquerading

ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware.

T1036.004
Masquerade Task or Service

ZIRCONIUM has created a run key named Dropbox Update Setup to mask a persistence mechanism for a malicious binary.

T1041
Exfiltration Over C2 Channel

ZIRCONIUM has exfiltrated files via the Dropbox API C2.

T1059.003
Windows Command Shell

ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.

T1059.006
Python

ZIRCONIUM has used Python-based implants to interact with compromised hosts.

T1068
Exploitation for Privilege Escalation

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1082
System Information Discovery

ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2.

T1090.003
Multi-hop Proxy

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1102.002
Bidirectional Communication

ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands.

T1105
Ingress Tool Transfer

ZIRCONIUM has used tools to download malicious files to compromised hosts.

T1124
System Time Discovery

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

View all 29 procedure examples

Software0

None recorded.

Campaigns0

None recorded.

References2

  1. Check Point APT31 February 2021 Open source
    Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021.
  2. Microsoft Targeting Elections September 2020 Open source
    Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.