Skip to content
// 01 — APT-INDEX RESEARCHER-MAINTAINED · LAST SYNC 11 MIN AGO

The canonical directory of 312 Chinese-nexus APT groups and gray-market exploit vendors.

ZeroDayCN maintains the only continuously updated, English-accessible catalog of threat actors with Chinese nexus — from state-aligned intrusions to commercial surveillance vendors and gray-market exploit brokers. Every entry is researcher-vetted, scored on a five-tier attribution confidence scale, and refreshed against live incident telemetry.

// INDEXED ACTORS 312 LIVE · +4 THIS WEEK
// HIGH-CONFIDENCE 68% TIER 4 + TIER 5 ATTRIBUTION
// STATE-ALIGNED 47 CONFIRMED CLUSTERS
// EXPLOIT VENDORS 29 GRAY-MARKET BROKERS
// 02 — ENTRY-ANATOMY

What every index record contains.

Each of the 312 entries is built to the same 14-field schema, so CTI engineers can pull comparable signals across actors without re-mapping fields. Below is the canonical record layout as it appears in the Threat Brief feed and in STIX 2.1 exports.

Identity & lineage

  • Canonical nameZeroDayCN-assigned primary handle (e.g., APT-31 / ZIRCONIUM).
  • AliasesUp to 12 tracked handles from vendor reports, with the original reporting vendor in monospace.
  • First-seenEarliest attributable incident or tool deployment, with source citation.
  • Last activityMost recent confirmed campaign, updated within 24 hours of detection.

Operational footprint

  • Target sectorsIndustries and verticals observed in the last 24 months, weighted by incident count.
  • Target regionsGeographic distribution of victims, mapped to ISO-3166 codes.
  • Active campaignsLive operation count with start date, status, and linked advisories.

Toolset & tradecraft

  • Malware familiesIndexed implants, loaders, and post-exploitation frameworks with first-seen and hash counts.
  • Exploit primitives0-day and n-day CVEs weaponized by the actor, cross-linked to our CVE catalog.
  • InfrastructureASN, hosting provider, and certificate reuse patterns observed in the last 90 days.

Attribution & sourcing

  • Confidence scoreFive-tier scale (Speculative → Confirmed), with the source weighting broken out per tier.
  • Source citationsEvery claim linked to a public report, internal telemetry, or a leak-derived document with date and analyst.
  • Analyst ownerNamed ZeroDayCN researcher responsible for the record and its refresh cadence.
  • Export formatsSTIX 2.1, MISP, JSON, CSV — identical payload, no schema drift between formats.
// 04 — METHODOLOGY

"Every attribution confidence score in the index is the output of a four-source triangulation — incident telemetry, leaked internal documents, vendor cross-reference, and binary re-use analysis. No entry is rated Tier 4 or higher on the basis of a single source. We publish the weighting matrix because the SOC teams consuming this feed should be able to audit the work, not just trust it."

— Dr. Lin Yueheng Head of Attribution, ZeroDayCN Research · ex-Pangu Lab
// 05 — TRUST-STATS

The dataset, by the numbers.

312 TOTAL ACTORS TRACKED 47 state-aligned · 236 criminal · 29 exploit vendors
68% TIER 4 + TIER 5 ATTRIBUTION Remaining 32% sits at Tier 3 with disclosed rationale
2.4 AVG. RECORD UPDATES / QTR Per actor, across aliases, tooling, and campaign status
2,100+ ENTERPRISE SOC SUBSCRIBERS Read-only feeds in 9 of top-10 domestic SIEM platforms
// 06 — CONVERT SUBSCRIPTION · THREAT BRIEF · ENTERPRISE

The full 312-group index sits behind the Threat Brief.

Subscribers get the complete catalog — every alias, every confidence score, every citation — plus real-time group tracking, infrastructure pivot maps, and exportable STIX 2.1 feeds for direct ingestion into your SIEM. Free weekly Threat Brief readers see a curated subset of 12 actors per issue; the index itself is gated.

  • Full 312-record index with searchable aliases
  • STIX 2.1 / MISP / JSON / CSV exports on every record
  • Real-time group-tracking alerts with delta diff
  • 24/7 on-call research hotline · 12-minute median response
// THREAT BRIEF · ENTERPRISE

Built for SOC analysts, CTI researchers, and red team operators who need validated, citation-backed intel — not headlines.

14-day evaluation · No card required · Cancel via email