Ke3chang

MITRE ATT&CK: G0004 View on attack.mitre.org

Aliases: APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, VIXEN PANDA, Ke3Chang, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, Red Vulture, Ke3chang, ke3chang, RedRiver

First seen
2010-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
14 (14 malicious)
Last IoC activity
2026-09-02 00:38:19
Profile updated
2026-07-07 12:33:39

Targeted industries: defense-and-aerospace government-and-public-sector energy-and-utilities education-and-nonprofits

Targeted regions: country_code:br country_code:co country_code:ve country_code:gb country_code:de country_code:fr country_code:us country_code:ca

Context

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.

Recent IoC activity

14 malicious indicators in Maltiverse are attributed to Ke3chang (G0004). The 14 most recently updated:

TypeIndicatorUpdatedSources
hostname mfaantivirus.xyz 2026-09-03 1
hostname pfs1010.com 2026-09-02 1
hostname pfs1010.xyz 2026-09-02 1
hostname update.adboeonline.net 2026-07-22 1
hostname scm.oracleapps.org 2026-06-26 1
file sample ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58 2026-06-25 1
hostname delldrivers.in 2026-06-18 1
file sample 20230118_67c911510e257b34.exe_ 2026-02-10 3
file sample 8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3 2025-12-17 1
hostname mail.indiarailways.net 2025-10-25 1
file sample 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa 2025-09-30 2
file sample 5bb99755924ccb6882fc0bdedb07a482313daeaaa449272dc291566cd1208ed5 2025-02-15 1
hostname update.delldrivers.in 2023-01-21 1
hostname www.delldrivers.in 2023-01-21 1

Detection coverage

  • 8 YARA rules
  • 992 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Local Account (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Golden Ticket (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Automated Collection (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • External Remote Services (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Security Account Manager (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Tool (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Service Execution (attack-pattern)
  • Data from Local System (attack-pattern)
  • DNS (attack-pattern)
  • Sharepoint (attack-pattern)

Reports & references

  • Mandiant — Apt Groups (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.com — Yir Cyber Threats Report Download (report)
  • Mandiant — Forced To Adapt Xslcmd Backdoor Now On Os X (report)
  • arstechnica.com — Elite Cyber Crime Group Strikes Back After Attack By Rival Apt Gang (report)
  • github.com — Royal Apt (report)
  • cfr.org — Mirage (report)
  • Mandiant — Wp Operation Ke3Chang (report)
  • Palo Alto Unit 42 — Operation Ke3Chang Resurfaces With New Tidepool Malware (report)
  • research.nccgroup.com — Apt15 Is Alive And Strong An Analysis Of Royalcli And Royaldns (report)
  • intezer.com — Miragefox Apt15 Resurfaces With New Tools Based On Old Ones (report)
  • MITRE ATT&CK — G0004 (report)
  • secureworks.com — Bronze Palace (report)
  • Microsoft — Rwmfii (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • web.archive.org — Miragefox Apt15 Resurfaces With New Tools Based On Old Ones (report)
  • Mandiant — Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs (report)
  • Microsoft — Nickel Targeting Government Organizations Across Latin America And Europe (report)

Attributed from

  • SPACEHOP Activity (campaign)
  • Wagemole (campaign)

External references