Chinese hackers APT31 have been linked to cyberattacks targeting Russia's IT sector . These attacks have been taking place since 2024 and the hackers manage to remain invisible for long periods of time.

“ From 2024 to 2025, the Russian IT sector, especially companies working as contractors and solution integrators for government agencies, faced a series of targeted attacks ,” said Positive Technologies researchers Daniil Grigoryan and Varvara Koloskova .
APT31: Brief history
APT31, also known as Altaire, Bronze Vinewood, Judgement Panda, PerplexedGoblin, RedBravo, Red Keres, and Violet Typhoon (formerly Zirconium), has been active since at least 2010. It has a history of attacks across a wide range of sectors, including government, financial services, aerospace and defense, high-tech, manufacturing and engineering, telecommunications, media, and insurance.
See also: Chinese APT24 distributes BADAUDIO malware
The cyber-espionage group focuses primarily on gathering information that can provide Beijing and state-owned enterprises with political, economic, and military advantages . In May 2025, the hacking group was accused by the Czech Republic of targeting its Foreign Ministry.
APT31: New attacks against Russia
Attacks against Russia are linked to the use of legitimate cloud services, mainly those widespread in the country, such as Yandex Cloud. The aim is to monitor and extract data, in an attempt to merge malicious activity with normal traffic to avoid detection.

The hackers are also said to have placed encrypted commands and payloads on social media profiles, both domestic and foreign, while conducting their attacks during weekends and holidays. In at least one attack targeting an IT company, APT31 breached the network in late 2022, before escalating activity over the 2023 New Year holidays.
In another attack detected in December 2024, threat actors sent a spear-phishing email containing a RAR file, which in turn contained a Windows Shortcut (LNK) responsible for launching a Cobalt Strike loader called CloudyLoader (via DLL side-loading). Details of this activity were previously documented by Kaspersky, and some overlaps were identified with a threat group known as EastWind.
See also: Iberia reveals data breach
The Russian cybersecurity firm also detected a decoy ZIP file that pretended to be a report from the Peruvian Ministry of Foreign Affairs. Its goal was to deploy CloudyLoader.

To facilitate the next stages of the attack cycle, APT31 has leveraged an extensive set of public and custom tools. Persistence is achieved by setting up scheduled tasks that mimic legitimate applications, such as Yandex Disk and Google Chrome. Some of these tools used include:
– SharpADUserIP, a C# tool for reconnaissance and discovery
– SharpChrome.exe, for extracting passwords and cookies from Google Chrome and Microsoft Edge browsers
– SharpDir, for searching files
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– StickyNotesExtract.exe, for extracting data from the Windows Sticky Notes database
– Tailscale VPN, to create an encrypted tunnel and set up a peer-to-peer (P2P) network between the compromised computer and their infrastructure
– Microsoft dev tunnels, for tunnel traffic
– Owawa, a malicious IIS module for credential theft
– AufTime, a backdoor for Linux that uses the wolfSSL library to communicate with C2
– COFFProxy, a Golang backdoor that supports commands for routing traffic, executing commands, managing files, and delivering additional payloads
– VtChatter, a tool that uses Base64-encoded comments in a text file hosted on VirusTotal (as a C2 channel every two hours)
– OneDriveDoor, a backdoor that uses Microsoft OneDrive as a C2
– LocalPlugX, a variant of PlugX used for propagation within the local network
– CloudSorcerer, a backdoor that uses cloud services as a C2
– YaLeak, a .NET tool for sending information to Yandex Cloud
See also: Over 370 organizations participate in GridEx VIII security exercise
“APT31 is constantly updating its arsenal: although it continues to use some of its old tools,” Positive Technologies said. “As a C2, the attackers are actively using cloud services, in particular Yandex and Microsoft OneDrive. Many tools are also configured to operate in server mode, waiting for attackers to connect to an infected host.”
