Ke3chang is malware associated with the Ke3chang threat activity cluster. Observed capabilities in the provided content include collecting the system language ID of a compromised machine; using batch scripts to install persistence mechanisms; performing service discovery with net start; conducting account discovery with commands such as net localgroup administrators and net group "REDACTED" /domain; performing local network connection discovery with netstat; gathering local network configuration with ipconfig; and enumerating running processes with tasklist. The content also states that Ke3chang transferred compressed and encrypted RAR files containing exfiltrated data through an established backdoor command-and-control channel. High-confidence targeting information, infection vector details, industries, and specific indicators of compromise are not provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ke3chang has used implants to collect the system language ID of a compromised machine.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"4H RAT sends an OS version identifier in its beacons"; "admin@338 actors used ... ver ... systeminfo"; "Bundlore will enumerate the macOS version ... using /usr/bin/sw_vers -productVersion"; "DarkTortilla ... querying ... WMI objects"; "Turla ... discover operating system configuration details using the systeminfo and set commands"
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that uses tasklist for process discovery.
Malware/tooling performing local network connection discovery via netstat.
Exfiltrates data as compressed/encrypted RAR archives over an established backdoor C2 channel.
Backdoor that performs local network configuration discovery via ipconfig.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.