Mirage is a Windows remote access trojan associated with the Chinese cyber-espionage group APT15, also known as Ke3chang, Vixen Panda, Royal APT, and Playful Dragon. It has been in use since at least 2012 and belongs to a broader cluster of closely related APT15 backdoors that includes Okrum, Ketrican, TidePool, Ketrum, and later MirageFox, reflecting the actor’s long-running practice of reusing and evolving lightweight implants for hands-on-keyboard operations.
Mirage is used to establish covert remote control over compromised systems and support espionage objectives. Reported functionality in Mirage-derived tooling includes collection of host information, execution of shell commands, file upload and download, process execution, and operator-directed backdoor control. Later variants linked to Mirage also demonstrate code reuse with other APT15 malware families and show continued refinement of command handling and communications.
Mirage has been observed in targeted intrusion activity rather than broad commodity crime operations. It has been detected in Southeast Asia and is associated with campaigns against government, military, telecommunications, transportation, and other high-value organizations, consistent with APT15’s wider targeting of diplomatic, defense, and strategic-sector entities across multiple regions. Delivery for Mirage specifically is not established at high confidence from the available facts, although related APT15 operations have used techniques such as DLL sideloading or hijacking after initial compromise. Overall, Mirage is best understood as part of APT15’s long-standing espionage toolkit for persistent remote access and manual post-compromise control on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ke3chang’s numerous tools such as Okrum, Ketrican, TidePool, Mirage, Ketrum, and others all serve the same purpose...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several Ke3chang tools under the broader BS2005 malware umbrella.
Targeted APT malware family detected in Southeast Asia during the reporting period.
Mirage is an older RAT family believed to originate in 2012 and associated here with APT15. It shares code and configuration decryption routines with MirageFox and supports remote shell execution and backdoor-style command handling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.