Ke3chang
Also known as: APT15 · Mirage · Vixen Panda · GREF · Playful Dragon · RoyalAPT · NICKEL · Nylon Typhoon
Overview
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
Naming & attribution
Ke3chang is tracked under 9 names across the industry. It uses 46 documented ATT&CK techniques — more than 81% of the 174 groups tracked here. Activity attributed since at least 2010.
| Name | First reported by |
|---|---|
| APT15 | Smallridge, R |
| Mirage | Smallridge, R |
| Vixen Panda | Smallridge, R |
| GREF | Smallridge, R |
| Playful Dragon | Smallridge, R |
| RoyalAPT | Rosenberg, J |
| NICKEL | MSTIC |
| Nylon Typhoon | Microsoft |
| Ke3Chang | Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1558.001Golden Ticket — used by 1 of 174 groups -
T1583.005Botnet — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Targets
Government
Regions
European Union · Germany · India · United Kingdom
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 46 techniques across 11 tactics
Initial Access
Execution
-
T1059Command and Scripting Interpreter -
T1059.003Windows Command Shell -
T1569.002Service Execution
Persistence
-
T1133External Remote Services -
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027Obfuscated Files or Information -
T1036.002Right-to-Left Override -
T1036.005Match Legitimate Resource Name or Location -
T1078Valid Accounts -
T1078.004Cloud Accounts -
T1140Deobfuscate/Decode Files or Information
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1003.003NTDS -
T1003.004LSA Secrets -
T1558.001Golden Ticket
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.002Domain Groups -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1614.001System Language Discovery
Lateral Movement
-
T1021.002SMB/Windows Admin Shares
Collection
-
T1005Data from Local System -
T1056.001Keylogging -
T1114.002Remote Email Collection -
T1119Automated Collection -
T1213.002Sharepoint -
T1560Archive Collected Data -
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer
Exfiltration
-
T1020Automated Exfiltration -
T1041Exfiltration Over C2 Channel
Tools & malware (11)
Ping · Okrum · Systeminfo · netstat · spwebmember · Mimikatz · Tasklist · MirageFox · Net · Neoichor · ipconfig