Also known as: APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, Ke3Chang, Social Network Team, Mirage Team, Lurid, Royal APT, Metushy, Winnti Umbrella, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, G0004, Red Vulture, TG-3279, China Cracking Group, RIVER CASTLE
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.(Citation: Mandiant Operation Ke3chang November 2014)(Citation: NCC Group APT15 Alive and Strong)(Citation: APT15 Intezer June 2018)(Citation: Microsoft NICKEL December 2021)
Umbrella Revolution
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Ke3chang is a Chinese-based advanced persistent threat (APT) group known for espionage activities targeting government, diplomatic, military, and gaming sectors globally since at least 2010. The group has been linked to multiple aliases and campaigns, including 'Mirage Team,' 'NICKEL,' and 'Umbrella Revolution.' Ke3chang employs a wide range of tactics, techniques, and procedures (TTPs) to infiltrate victim networks, collect sensitive data, and maintain long-term access.
Goals & Targeting
Ke3 chang's primary strategic objective appears to be gathering intelligence and sensitive information from targeted sectors such as government, military, and gaming industries. The group's focus on these sectors suggests a desire to acquire geopolitical, defense-related, and potentially commercially valuable data. Targeted countries include the United States, South America, Europe, and others, indicating a global scope of operations. The group likely operates under the direction of Chinese state interests, aiming to support national security or economic goals.
Enhanced Description
Ke3chang is a state-sponsored cyberespionage group attributed to Chinese actors. The group has demonstrated significant operational persistence since its first identification by Mandiant in 2014 as Operation Ke3 Chang. Known for its ties to the Chinese government, Ke3chang primarily focuses on stealing sensitive information from diplomatic entities, defense contractors, and critical infrastructure sectors such as energy and gaming industries. Over the years, the group has expanded its targeting to include not just traditional espionage targets but also global organizations in Central and South America, Europe, and North America. The group's TTPs include extensive use of credential theft, lateral movement within networks, and persistence mechanisms that leverage Windows-based techniques. Its toolset includes custom malware and scripts designed for long-term access and data exfiltration. Despite its long operational history, Ke3chang has managed to remain under the radar in many cases due to its sophisticated TTPs.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ke3chang has been involved in several high-profile campaigns, including Operation Ke3 Chang identified by Mandiant and APT15 activities noted by multiple security firms. The group often targets organizations with spear-phishing emails, deploying custom tools to gain initial access before using a range of techniques to expand across networks. Campaigns frequently involve long-term驻留 within victim networks, enabling sustained data collection and exfiltration over time. Notable operations have targeted oil and gas industries, government agencies, and gaming companies globally.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Ke3chang's existence and activity due to multiple independent reports from reputable security firms, including Mandiant and Microsoft. However, details regarding the group's recent activities beyond 2021 are limited, and specific campaign attributes may require further confirmation.
Umbrella Revolution
No observed data linked yet.
No IOCs linked yet.
46
Techniques
18
Tools
1
Campaigns
0
IOCs
0
Observed Data
11
Tactics