Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ke3chang

Also known as: APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, Ke3Chang, Social Network Team, Mirage Team, Lurid, Royal APT, Metushy, Winnti Umbrella, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, G0004, Red Vulture, TG-3279, China Cracking Group, RIVER CASTLE

Description

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.(Citation: Mandiant Operation Ke3chang November 2014)(Citation: NCC Group APT15 Alive and Strong)(Citation: APT15 Intezer June 2018)(Citation: Microsoft NICKEL December 2021)

TTP Summary

Umbrella Revolution

Goals & Targeting

Targeted Sectors

Government
Gaming

Targeted Countries / Regions

GB

AI Analysis

· 1 week ago

Executive Summary

Ke3chang is a Chinese-based advanced persistent threat (APT) group known for espionage activities targeting government, diplomatic, military, and gaming sectors globally since at least 2010. The group has been linked to multiple aliases and campaigns, including 'Mirage Team,' 'NICKEL,' and 'Umbrella Revolution.' Ke3chang employs a wide range of tactics, techniques, and procedures (TTPs) to infiltrate victim networks, collect sensitive data, and maintain long-term access.

Goals & Targeting

Ke3 chang's primary strategic objective appears to be gathering intelligence and sensitive information from targeted sectors such as government, military, and gaming industries. The group's focus on these sectors suggests a desire to acquire geopolitical, defense-related, and potentially commercially valuable data. Targeted countries include the United States, South America, Europe, and others, indicating a global scope of operations. The group likely operates under the direction of Chinese state interests, aiming to support national security or economic goals.

Enhanced Description

Ke3chang is a state-sponsored cyberespionage group attributed to Chinese actors. The group has demonstrated significant operational persistence since its first identification by Mandiant in 2014 as Operation Ke3 Chang. Known for its ties to the Chinese government, Ke3chang primarily focuses on stealing sensitive information from diplomatic entities, defense contractors, and critical infrastructure sectors such as energy and gaming industries. Over the years, the group has expanded its targeting to include not just traditional espionage targets but also global organizations in Central and South America, Europe, and North America. The group's TTPs include extensive use of credential theft, lateral movement within networks, and persistence mechanisms that leverage Windows-based techniques. Its toolset includes custom malware and scripts designed for long-term access and data exfiltration. Despite its long operational history, Ke3chang has managed to remain under the radar in many cases due to its sophisticated TTPs.

Key Capabilities

  • Spear-phishing with malicious attachments
  • Credential theft
  • Lateral network movement
  • Data exfiltration via custom tools
  • Domain and account compromise
  • Persistence mechanisms

MITRE ATT&CK Tactics

Credential Access
Discovery
Exfiltration
Persistence

ATT&CK Techniques

T1059.003
T1213.002
T1087.002
T1041
T1543
T1005
T1614.001
T1558.001

Software / Tooling

Okrum
MirageFox
Neoichor
Custom malware

Campaigns & Victims

Ke3chang has been involved in several high-profile campaigns, including Operation Ke3 Chang identified by Mandiant and APT15 activities noted by multiple security firms. The group often targets organizations with spear-phishing emails, deploying custom tools to gain initial access before using a range of techniques to expand across networks. Campaigns frequently involve long-term驻留 within victim networks, enabling sustained data collection and exfiltration over time. Notable operations have targeted oil and gas industries, government agencies, and gaming companies globally.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • Lateral movement using Windows command-line executables
  • Exfiltration through encrypted channels or legitimate cloud services
  • Malicious scripts dropped via web protocols
  • Credential dumping operations targeting domain accounts

Recommended Actions

  • Implement multi-layered email filtering to detect and block spear-phishing attempts.
  • Monitor for unusual network activity, especially lateral movement patterns indicative of APT behavior.
  • Enhance credential protection with MFA (Multi-Factor Authentication) and regular password audits.
  • Deploy endpoint detection and response (EDR) solutions to detect malicious scripts and processes.
  • Conduct regular red team exercises simulating APT tactics to improve incident response readiness.

Suggested Tags

APT
espionage
state-sponsored
gaming-sector
government-targeting

Confidence Assessment

High confidence in Ke3chang's existence and activity due to multiple independent reports from reputable security firms, including Mandiant and Microsoft. However, details regarding the group's recent activities beyond 2021 are limited, and specific campaign attributes may require further confirmation.

ATT&CK Techniques

Collection
7 techniques
Credential Access
5 techniques
Discovery
12 techniques
Stealth
6 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  2. Microsoft NICKEL December 2021 — MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.
  3. APT15 Intezer June 2018 — Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.
  4. NCC Group APT15 Alive and Strong — Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.
  5. Mandiant Operation Ke3chang November 2014 — Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
  6. Villeneuve et al 2014 — Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.

Intel Summary

46

Techniques

18

Tools

1

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

APT
Government Targeting
espionage
state-sponsored
gaming-sector
government-targeting

Details

MITRE ID
G0004
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6713ab67-e25b-49cc-808d-2b36d4fbc35c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.