APT-31 / ZIRCONIUM
aka Judgment Panda, RedAlpha, APT-C-01
- 14 malware families
- 9 weaponized CVEs
- 3 leak-derived doc ties
ZeroDayCN maintains the only continuously updated, English-accessible catalog of threat actors with Chinese nexus — from state-aligned intrusions to commercial surveillance vendors and gray-market exploit brokers. Every entry is researcher-vetted, scored on a five-tier attribution confidence scale, and refreshed against live incident telemetry.
Each of the 312 entries is built to the same 14-field schema, so CTI engineers can pull comparable signals across actors without re-mapping fields. Below is the canonical record layout as it appears in the Threat Brief feed and in STIX 2.1 exports.
APT-31 / ZIRCONIUM).A snapshot from the live index. Subscriber records additionally include malware family graphs, infrastructure pivot maps, and 90-day hunt-package queries.
aka Judgment Panda, RedAlpha, APT-C-01
aka DSX, DeedSword Exploit Hub, SwordBroker-04
aka Tropic Trooper, KeyBoy, Pirate Panda
"Every attribution confidence score in the index is the output of a four-source triangulation — incident telemetry, leaked internal documents, vendor cross-reference, and binary re-use analysis. No entry is rated Tier 4 or higher on the basis of a single source. We publish the weighting matrix because the SOC teams consuming this feed should be able to audit the work, not just trust it."
Subscribers get the complete catalog — every alias, every confidence score, every citation — plus real-time group tracking, infrastructure pivot maps, and exportable STIX 2.1 feeds for direct ingestion into your SIEM. Free weekly Threat Brief readers see a curated subset of 12 actors per issue; the index itself is gated.
Built for SOC analysts, CTI researchers, and red team operators who need validated, citation-backed intel — not headlines.
14-day evaluation · No card required · Cancel via email