Ketrican
- First seen
- 2018-07-15 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:40:38
Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities financial-services
Targeted regions: country_code:us country_code:gb country_code:de country_code:in
Context
Ketrican is a sophisticated backdoor trojan attributed to the cyber-espionage group APT 15. It is designed to provide persistent access to compromised systems, primarily targeting government and sensitive industry sectors.
Detection coverage
- 3 YARA rules
Detection rules
- SIGNATURE_BASE_APT_KE3CHANG_TMPFILE (yara-rule)
- SIGNATURE_BASE_APT_MAL_Ke3Chang_Ketrican_Jun20_1 (yara-rule)
- MALPEDIA_Win_Ketrican_Auto (yara-rule)
Reports & references
- ptsecurity.com — Antisandbox Techniques (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ketrican (report)
- intezer.com — The Evolution Of Apt15S Codebase 2020 (report)
- ESET — Okrum Ke3Chang Targets Diplomatic Missions (report)
- verfassungsschutz.de — Broschuere 2020 06 Bfv Cyber Brief 2020 01 (report)