# APT31

> As of 2026-10-10, APT31 is a China (PRC)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as TA412, UNK_DoubleCheck, UNK_QuietRacket, UTA0560. ATT&CK coverage spans 53 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1055 (Process Injection), T1203 (Exploitation for Client Execution).

- **Nation:** China (PRC)
- **Tracked threats:** 2
- **Categories:** VULNERABILITY, APT
- **Also known as:** TA412, UNK_DoubleCheck, UNK_QuietRacket, UTA0560, Violet Typhoon, Zirconium, Judgment Panda, Bronze Vinewood, Red Keres
- **As of:** 2026-10-10

## ATT&CK techniques observed

53 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (8), Stealth (formerly Defense Evasion) (8), Execution (7), Initial Access (5), Reconnaissance (5), Collection (4).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Privilege Escalation — observed in 2 of 2 tracked threats
- [T1203](https://intel.threadlinqs.com/technique/T1203) Exploitation for Client Execution — Execution — observed in 2 of 2 tracked threats
- [T1204.001](https://intel.threadlinqs.com/technique/T1204.001) Malicious Link — Execution — observed in 2 of 2 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027.002](https://intel.threadlinqs.com/technique/T1027.002) Software Packing — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 1 of 2 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Credential Access — observed in 1 of 2 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats

## Tracked threats

- [BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880](https://intel.threadlinqs.com/threat/TL-2026-3185) — CRITICAL
- [APT31 Weaponizes Google Gemini AI for Automated Cyberattack Planning](https://intel.threadlinqs.com/threat/TL-2026-0085) — CRITICAL

## Related CVEs

4 CVEs referenced by tracked APT31 activity.

- [CVE-2026-87491](https://intel.threadlinqs.com/cve/CVE-2026-87491)
- [CVE-2026-85880](https://intel.threadlinqs.com/cve/CVE-2026-85880)
- [CVE-2026-85046](https://intel.threadlinqs.com/cve/CVE-2026-85046)
- [CVE-2025-7775](https://intel.threadlinqs.com/cve/CVE-2025-7775)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT31
