Ke3chang
MITRE ATT&CK: G0004 View on attack.mitre.org
Aliases: APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, VIXEN PANDA, Ke3Chang, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, Red Vulture, Ke3chang, ke3chang, RedRiver
- First seen
- 2010-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 14 (14 malicious)
- Last IoC activity
- 2026-09-02 00:38:19
- Profile updated
- 2026-07-07 12:33:39
Targeted industries: defense-and-aerospace government-and-public-sector energy-and-utilities education-and-nonprofits
Targeted regions: country_code:br country_code:co country_code:ve country_code:gb country_code:de country_code:fr country_code:us country_code:ca
Context
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
Recent IoC activity
14 malicious indicators in Maltiverse are attributed to Ke3chang (G0004). The 14 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | mfaantivirus.xyz | 2026-09-03 | 1 |
| hostname | pfs1010.com | 2026-09-02 | 1 |
| hostname | pfs1010.xyz | 2026-09-02 | 1 |
| hostname | update.adboeonline.net | 2026-07-22 | 1 |
| hostname | scm.oracleapps.org | 2026-06-26 | 1 |
| file sample | ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58 | 2026-06-25 | 1 |
| hostname | delldrivers.in | 2026-06-18 | 1 |
| file sample | 20230118_67c911510e257b34.exe_ | 2026-02-10 | 3 |
| file sample | 8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3 | 2025-12-17 | 1 |
| hostname | mail.indiarailways.net | 2025-10-25 | 1 |
| file sample | 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa | 2025-09-30 | 2 |
| file sample | 5bb99755924ccb6882fc0bdedb07a482313daeaaa449272dc291566cd1208ed5 | 2025-02-15 | 1 |
| hostname | update.delldrivers.in | 2023-01-21 | 1 |
| hostname | www.delldrivers.in | 2023-01-21 | 1 |
Detection coverage
- 8 YARA rules
- 992 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Local Account (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- System Language Discovery (attack-pattern)
- Domain Account (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Golden Ticket (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Automated Collection (attack-pattern)
- File and Directory Discovery (attack-pattern)
- External Remote Services (attack-pattern)
- Remote System Discovery (attack-pattern)
- Security Account Manager (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Tool (attack-pattern)
- Automated Exfiltration (attack-pattern)
- System Service Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Service Execution (attack-pattern)
- Data from Local System (attack-pattern)
- DNS (attack-pattern)
- Sharepoint (attack-pattern)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.com — Yir Cyber Threats Report Download (report)
- Mandiant — Forced To Adapt Xslcmd Backdoor Now On Os X (report)
- arstechnica.com — Elite Cyber Crime Group Strikes Back After Attack By Rival Apt Gang (report)
- github.com — Royal Apt (report)
- cfr.org — Mirage (report)
- Mandiant — Wp Operation Ke3Chang (report)
- Palo Alto Unit 42 — Operation Ke3Chang Resurfaces With New Tidepool Malware (report)
- research.nccgroup.com — Apt15 Is Alive And Strong An Analysis Of Royalcli And Royaldns (report)
- intezer.com — Miragefox Apt15 Resurfaces With New Tools Based On Old Ones (report)
- MITRE ATT&CK — G0004 (report)
- secureworks.com — Bronze Palace (report)
- Microsoft — Rwmfii (report)
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- web.archive.org — Miragefox Apt15 Resurfaces With New Tools Based On Old Ones (report)
- Mandiant — Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs (report)
- Microsoft — Nickel Targeting Government Organizations Across Latin America And Europe (report)
Attributed from
- SPACEHOP Activity (campaign)
- Wagemole (campaign)
External references
- mitre-attack — G0004
- RoyalAPT
- NICKEL
- Nylon Typhoon
- APT15
- Mirage
- GREF
- Vixen Panda
- Playful Dragon
- Ke3chang
- Microsoft Threat Actor Naming July 2023
- Microsoft NICKEL December 2021
- APT15 Intezer June 2018
- NCC Group APT15 Alive and Strong
- Mandiant Operation Ke3chang November 2014
- Villeneuve et al 2014
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy