Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

U.S. Treasury Sanctions China-Linked APT31 Personnel and Wuhan Company

On March 25, 2024, the U.S. sanctioned Wuhan XRZ and two people Treasury linked to APT31, while DOJ charged seven Chinese nationals. Here is what the measures mean and what organizations should know.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 25, 2024, the U.S. Treasury Department sanctioned Wuhan Xiaoruizhi Science and Technology Company, Limited (Wuhan XRZ), and two people Treasury linked to APT31: Zhao Guangzong and Ni Gaobin. On the same day, the Justice Department unsealed charges against seven Chinese nationals alleged to be associated with the group, while the United Kingdom announced separate sanctions and cyber-attribution findings. The actions were aimed at alleged cyberespionage—not a blanket ban on Chinese businesses—and criminal charges were allegations, not convictions.

What happened on March 25, 2024?

The announcement comprised three related but legally distinct actions:

  • U.S. sanctions: The Treasury Department’s Office of Foreign Assets Control (OFAC) designated Wuhan XRZ, Zhao Guangzong, and Ni Gaobin. Treasury described the Wuhan-based company as a front for China’s Ministry of State Security (MSS), specifically the Hubei State Security Department. The designations were made under Executive Order 13694, as amended by Executive Order 13757. Treasury’s announcement.
  • U.S. criminal case: The Justice Department unsealed charges against seven Chinese nationals alleged to be connected to APT31, including Zhao and Ni. The charges included conspiracy to commit computer intrusions and wire fraud. The DOJ announcement.
  • UK measures: The UK sanctioned Wuhan XRZ and two individuals and made separate public findings about cyber activity affecting UK democratic institutions. The UK government statement.

These measures did not establish that every incident attributed to APT31 involved the three OFAC designees. Nor did the UK findings about UK systems establish that those incidents were the same operation as the U.S. allegations.

What is APT31?

APT31 is a China-linked cyberespionage label used by governments and security researchers, not the name of a publicly established corporation with a fixed membership roster. Treasury characterized the activity as involving Chinese intelligence personnel, contract hackers, and support staff working on behalf of the Hubei State Security Department. Personnel, infrastructure, and the scope of a group label can change over time, and different organizations may use different labels or boundaries.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Treasury said Wuhan XRZ was established in 2010 and functioned as a front company supporting cyber operations. It alleged that company employees supported operations against U.S. and foreign targets, including an unauthorized intrusion into a Texas-based energy company in 2018. These are government attributions and allegations, not findings established by a criminal conviction.

Who was sanctioned, and what did Treasury allege?

Wuhan XRZ

Treasury identified Wuhan XRZ as a company used to support cyber operations. It linked the company to surveillance and intrusion activity involving government and political figures, policy experts, academics, journalists, activists, and businesses. Treasury also alleged that employees gained unauthorized access to a Texas-based energy company in 2018.

Zhao Guangzong and Ni Gaobin

Treasury described Zhao as a Wuhan XRZ contractor who conducted malicious cyber operations and attributed a 2020 spear-phishing operation targeting the U.S. Naval Academy and the U.S. Naval War College’s China Maritime Studies Institute to him. Treasury said Ni, who was affiliated with Wuhan XRZ, assisted Zhao in several high-profile operations, including that campaign.

DOJ’s case was broader than the OFAC designations: it charged seven people. The indictment’s allegations must be proved in court; the DOJ announcement did not report convictions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did U.S. authorities say the campaign targeted?

Treasury listed targets across government, defense, business, and civil society. Its account included White House staff; the departments of Justice, Commerce, Treasury, and State; members of Congress from both parties; the Naval Academy and the Naval War College’s China Maritime Studies Institute; Defense Industrial Base organizations; information-technology and energy companies; and managed service providers. Treasury also described targeting of political dissidents, academics, journalists, and democracy activists.

DOJ said the alleged campaign had operated since at least 2010, targeted thousands of individuals and companies, and involved more than 10,000 malicious emails. According to DOJ, some emails used disguised tracking links to gather information about recipients before more targeted intrusion attempts. The department said opened messages could transmit information such as IP addresses, location data, network details, and device information.

How did the alleged operations work?

The government accounts describe a mix of social engineering, reconnaissance, and exploitation of trusted access rather than a single type of attack. Alleged methods included:

  • Spear-phishing messages, including messages impersonating journalists or news organizations.
  • Malicious or tracking links used to gather information about recipients and select targets for follow-on activity.
  • Intrusions involving email, cloud storage, routers, and other network-connected devices.
  • Long-term surveillance of compromised accounts.
  • Access through managed service providers and other trusted intermediaries, which can expose more than one customer.

These descriptions explain why the alleged activity mattered to organizations beyond those directly named: attackers seeking intelligence can pursue identities, suppliers, and service providers as routes to valuable information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did the sanctions actually do?

An OFAC designation is an economic and administrative measure, not a criminal conviction. In general, property and interests in property belonging to a designated person or entity are blocked if they are in the United States or in the possession or control of a U.S. person. U.S. persons generally may not transact with blocked parties unless OFAC authorizes the activity. Funds, goods, or services provided to or for the benefit of a blocked party can also create sanctions exposure.

OFAC’s 50 Percent Rule generally treats an entity as blocked when one or more blocked persons own, directly or indirectly, 50% or more of it, individually or in aggregate. Ownership and identifying details therefore matter; a business should not rely on a name-only match or assume a company is clear because it is not separately named on a list.

The designations did not prohibit all business with China, every company in Wuhan, or everyone sharing a common name with Zhao or Ni. Sanctions screening requires careful matching of names, aliases, identifying information, and ownership. Some activities may be excepted or licensed, depending on the circumstances; organizations with a potential match should consult current OFAC guidance and qualified sanctions counsel. Foreign financial institutions and other parties may also face sanctions or enforcement risk for certain dealings.

How are sanctions different from criminal charges?

Action Authority What it means
OFAC designation U.S. Treasury An administrative economic measure that blocks covered property and generally restricts transactions by U.S. persons.
Indictment U.S. Department of Justice A formal accusation of criminal offenses. It is not proof of guilt; defendants are presumed innocent unless proven guilty in court.
Rewards offer U.S. State Department An appeal for information that could support disruption or prosecution; it is not a finding of guilt.
UK sanctions UK Foreign, Commonwealth & Development Office Financial restrictions under UK law, separate from U.S. sanctions.

A sanctions designation can take effect without a criminal conviction. Conversely, an indictment begins a prosecution process and does not itself block property under OFAC rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did the UK add?

The UK statement addressed two strands of activity. The UK’s National Cyber Security Centre assessed that a China state-affiliated actor had highly likely compromised UK Electoral Commission systems between 2021 and 2022. It also assessed that APT31 had almost certainly conducted reconnaissance against UK parliamentarians in 2021, while stating that no parliamentary accounts were successfully compromised in that campaign. The UK sanctioned Wuhan XRZ and two individuals. The NCSC’s account and the UK government announcement set out those findings.

The UK assessments provide allied context, but the Electoral Commission compromise, parliamentary reconnaissance, and U.S. targets should not be collapsed into one intrusion. The wording of the UK assessments also matters: “highly likely” and “almost certainly” express attributed judgments, not direct proof in a criminal trial.

What should organizations do about this kind of threat?

The sanctions do not stop cyber activity by themselves. Organizations should focus on reducing the ways an espionage operation could reach high-value accounts, sensitive data, and trusted suppliers.

Protect identities and email

  • Require phishing-resistant multifactor authentication for privileged and high-value accounts where available.
  • Separate administrative accounts from everyday accounts and apply conditional access controls.
  • Monitor unusual mailbox forwarding rules, OAuth grants, sign-ins, and session activity.
  • Train staff to verify unexpected links and messages through a separate trusted channel, especially when a message appears to come from a journalist, partner, or senior colleague.

Reduce exposure through suppliers

  • Review managed service provider, remote-support, identity-provider, and cloud-vendor access; remove accounts and privileges that are no longer needed.
  • Ask providers how they protect administrative access and notify customers of suspected compromise.
  • Identify where one supplier has access across multiple business units or customers, and plan how to isolate that access quickly.

Keep the evidence needed to investigate

  • Retain authentication, email, endpoint, DNS, VPN, and identity-provider logs long enough to investigate activity that may unfold slowly.
  • Test the ability to revoke credentials, sessions, and tokens; isolate affected accounts; and preserve evidence during an incident.
  • Harden internet-facing services and monitor endpoints and cloud environments for suspicious access.
  • Set an incident-reporting path to the FBI, CISA, or the relevant national authority.

Screen counterparties separately from threat monitoring

Maintain sanctions-screening procedures for vendors, customers, owners, and other counterparties using current lists and ownership checks. That compliance process is distinct from cyber defense: a company can face APT31-style risk without transacting with a sanctioned party, and a vendor’s absence from a public sanctions list does not establish that it is secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the action means—and what it does not establish

The coordinated measures publicly identified alleged personnel, a company, and a long-running campaign, while imposing financial restrictions and pursuing criminal charges. They also signaled that U.S. and UK authorities were willing to attribute activity against government, political, and critical-infrastructure targets. The announcements alone do not show that the activity stopped or that sanctions deterred future operations.

The U.S. and UK statements are official government assessments and allegations. The DOJ defendants were charged, not convicted, and the group label APT31 does not prove that every operation attributed to it involved the designated company or individuals.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.