← threatfilter.dev / all groups / Ke3chang
Ke3chang
Also known as: APT15 · Mirage · Vixen Panda · GREF · Playful Dragon · RoyalAPT · NICKEL · Nylon Typhoon
Overview
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
Targets
Government
Regions
European Union · Germany · India · United Kingdom
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 46 techniques across 11 tactics
Initial Access
Execution
-
T1059Command and Scripting Interpreter -
T1059.003Windows Command Shell -
T1569.002Service Execution
Persistence
-
T1133External Remote Services -
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027Obfuscated Files or Information -
T1036.002Right-to-Left Override -
T1036.005Match Legitimate Resource Name or Location -
T1078Valid Accounts -
T1078.004Cloud Accounts -
T1140Deobfuscate/Decode Files or Information
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1003.003NTDS -
T1003.004LSA Secrets -
T1558.001Golden Ticket
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.002Domain Groups -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1614.001System Language Discovery
Lateral Movement
-
T1021.002SMB/Windows Admin Shares
Collection
-
T1005Data from Local System -
T1056.001Keylogging -
T1114.002Remote Email Collection -
T1119Automated Collection -
T1213.002Sharepoint -
T1560Archive Collected Data -
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer
Exfiltration
-
T1020Automated Exfiltration -
T1041Exfiltration Over C2 Channel
Tools & malware (11)
Ping · Okrum · Systeminfo · netstat · spwebmember · Mimikatz · Tasklist · MirageFox · Net · Neoichor · ipconfig