Ke3chang is a China-nexus threat actor also tracked as APT15, GREF, Vixen Panda, Nickel, Playful Dragon, Playful Taurus, RoyalAPT, Mirage, Flea, Bronze Palace, Bronze Davenport, Bronze Idlewood, and Social Network Team. The group has used custom malware and remote-access capabilities to maintain persistence on victim networks. Its documented post-compromise tradecraft includes command-line execution; process discovery using tasklist; operating-system, system-language, computer-name, and signed-in-user discovery; local network-configuration discovery using ipconfig; and searching files and directories. Ke3chang has exfiltrated compressed and encrypted RAR archives through an established backdoor command-and-control channel. Its RoyalCli and BS2005 malware have communicated with command-and-control infrastructure over HTTP through Internet Explorer COM automation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
61 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
17 CVEs this actor has used in observed campaigns. 17 of them exploited in the wild.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
The weaponized document sent in phishing emails triggers the vulnerability outlined in CVE-2015-2545, which was first made public in September 2015... The TidePool malware is housed in an MHTML document which exploits CVE-2015-2545.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
12 more CVEs tied to this actor tracked in Mallory.
254 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited in connection with Rclone use in cloud data-theft incidents.
Listed in the detection's Annotations section.
Referenced as a predecessor-linked ransomware group whose former members are believed to be connected to the Chaos ransomware operation.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.