RoyalCli is a custom Windows backdoor associated with the China-linked espionage group APT15, also tracked as Ke3chang, Mirage, Vixen Panda, GREF, Playful Dragon, Nickel, and Flea. It was identified during NCC Group’s investigation of a May 2017 compromise of a company providing services to the UK Government, where attackers stole sensitive documents assessed to relate to UK government departments and military technology. RoyalCli was deployed alongside BS2005 and RoyalDNS, and is assessed to be an evolution of APT15’s older BS2005 backdoor, reusing similar encryption and encoding routines.
RoyalCli communicates with command-and-control infrastructure over HTTP using Internet Explorer through the COM interface IWebBrowser2. This technique caused C2 data to be cached on disk by the IE process, which enabled investigators to recover and decode attacker tasking. Reported RoyalCli C2 domains include News.memozilla[.]org and video.memozilla[.]org. In the referenced intrusion, APT15 used RoyalCli as part of a broader post-compromise toolkit that also included keyloggers, Mimikatz, a .NET Exchange mailbox dumping tool, a bespoke SharePoint data theft tool named spwebmember, WinRAR, and a RemoteExec utility similar to PsExec.
Persistence for RoyalCli required attackers to create batch scripts that installed a simple Windows Run key. NCC Group assessed this batch-scripted persistence may have been intended to evade behavioral detection. The malware name derives from a PDB/debug path recovered from a sample: c:\users\wizard\documents\visual studio 2010\Projects\RoyalCli\Release\RoyalCli.pdb.
RoyalCli is part of APT15’s long-running espionage toolset used against government, diplomatic, and military-related targets. High-confidence indicators directly mentioned in the content include the PDB path above and the C2 domains News.memozilla[.]org and video.memozilla[.]org.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
their malicious functionality is primarily concentrated in backdoors like RoyalCli and RoyalDNS
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RoyalCli is a backdoor malware used by APT15 to maintain access and exfiltrate data from compromised networks.
Custom backdoor used by APT15 as part of its malware arsenal for covert access.
Custom APT15 implant/backdoor referenced as part of the group’s historical tooling.
APT15 backdoor assessed as an evolution of BS2005. Communicates with C2 through Internet Explorer via the IWebBrowser2 COM interface (with C2 artifacts cached to disk by IE). Uses batch scripts to set persistence via a Windows Run key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.