logo

Walking on APT31 infrastructure footprints

ID: 57c8baf9-8837-5ebb-bb12-ba21fe56264c

STIX ID: report--57c8baf9-8837-5ebb-bb12-ba21fe56264c

Feed Name: Sekoia.com

Threat Score
85/100

Date Published: 2021-11-10

Date Updated: 2026-07-20

...
...

This Sekoia intelligence brief analyzes APT31 activity observed in 2021, documenting their use of compromised SOHO routers (Pakedge and others) as Operational Relay Boxes, delivery and use of implants including Cobalt Strike and TinySHell-like ELF backdoors, DNS/registrant heuristics to identify C2 domains, and provides a list of domains, IPs and YARA rules to aid hunting; it contextualizes attribution to Chinese state‑linked actors and notes the shift in infrastructure tactics since mid‑2021.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.