Ke3chang is a long-running Chinese state-sponsored cyber espionage threat actor associated with intelligence collection operations against government, diplomatic, defense, energy, telecommunications, and other strategic-sector targets, particularly in Asia, Europe, and the Middle East. The group is widely tracked under multiple aliases including APT15, Vixen Panda, Nickel, Nylon Typhoon, Playful Dragon, Playful Taurus, Royal APT, Mirage, Flea, Metushy, GREF, Bronze Palace, Bronze Davenport, Bronze Idlewood, Red Vulture, and RedRiver. The actor is known for sustained espionage activity rather than financially motivated operations. Its operations commonly involve custom backdoors and implants, long-term persistence, victim profiling, and post-compromise reconnaissance. Reported tradecraft includes system information discovery using native utilities such as systeminfo, collection of host metadata including computer name and operating system details, and identification of system language or language ID to profile victims and guide execution. Ke3chang has also conducted file and directory discovery through command-line interaction. For persistence, Ke3chang malware has been observed using Windows autostart mechanisms such as Registry Run keys, and some backdoors have established persistence through Windows services. RoyalDNS, a backdoor associated with the group, has been reported to persist as a service. Broader ATT&CK-aligned reporting also associates the actor with command execution, proxy-based command-and-control techniques, exploitation for privilege escalation, and service-based persistence. Ke3chang is best understood as an espionage-focused intrusion set within the Chinese nexus of advanced persistent threat activity. Although naming overlaps in public reporting can create alias ambiguity, Ke3chang is consistently recognized by defenders as a mature, state-linked actor conducting targeted intelligence collection with customized malware, stealthy persistence, and methodical host reconnaissance.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
65 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
48 malware families attributed to this actor across reporting.
43 additional families tracked in Mallory.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
11 more CVEs tied to this actor tracked in Mallory.
93 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware operations that received attack infrastructure and technical support from the bulletproof hosting providers Media Land and ML.Cloud.
Named as a ransomware gang that used the sanctioned bulletproof hosting providers' infrastructure.
Named as a ransomware group that used Media Land and ML Cloud bulletproof hosting services.
Named as one of the ransomware groups that allegedly used Media Land and ML.Cloud bulletproof hosting infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.