Researchers linked the Chinese-aligned espionage group Ke3chang/APT15 to a sustained campaign against diplomatic organizations, tying together older RoyalDNS and RoyalCLI activity with newer Ketrican malware and a previously undocumented backdoor named Okrum. ESET reported that Okrum was first detected in late 2016 and used against diplomatic missions in Slovakia, Belgium, Chile, Guatemala, and Brazil, extending a broader pattern of targeting government and foreign affairs entities in Europe and Latin America that earlier reporting had associated with Operation Ke3chang.
The malware set shows an actor that has refreshed its tooling while preserving tradecraft across multiple years. Okrum provides basic backdoor access and depends heavily on manually executed shell commands and external utilities, while related tools used evasion techniques including payloads hidden in PNG files, anti-sandbox checks, and frequently changed loaders. Combined reporting from ESET, NCC Group, FireEye, and Intezer indicates APT15 remained active from at least 2015 through 2019, resurfacing with updated implants derived from older ones as it continued cyberespionage operations against diplomatic targets.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
Intezer reported a newly identified malware family named Ketrum and attributed it to Ke3chang/APT15 based on shared code and infrastructure with the older Ketrican and Okrum backdoors. The report said samples uploaded in December 2019 and May 2020 showed Ketrum as a hybrid evolution of those malware families.
In March 2019, ESET detected a new Ketrican sample that evolved from the 2018 Ketrican backdoor and attacked the same targets.
ESET discovered a new Ketrican backdoor version in 2018 that included code improvements over earlier variants.
In 2017, the same entities affected by Okrum and the 2015 Ketrican activity were targeted again using RoyalDNS and a Ketrican backdoor compiled that year.
During 2017, Okrum was used against diplomatic missions in Slovakia, Belgium, Chile, Guatemala, and Brazil, with particular focus on Slovak targets.
ESET first detected the previously undocumented Okrum backdoor in December 2016 and linked it to the Ke3chang threat group.
In May 2016, Unit 42 reported that Operation Ke3chang was still active and identified TidePool as a new malware family evolved from the group's earlier BS2005 malware. The campaign targeted Indian embassy personnel worldwide with spear-phishing MHTML documents exploiting CVE-2015-2545.
In 2015, ESET identified suspicious activity in European countries including Slovakia, Croatia, and the Czech Republic involving malware it later referred to as Ketrican. The malware showed ties to BS2005 backdoors from Operation Ke3chang and to the TidePool family.
A FireEye report published in 2013 documented Operation Ke3chang and its targeting of diplomatic organizations in Europe.
FireEye documented Operation Ke3chang as targeting diplomatic organizations in Europe and traced Ke3chang activity back to 2010.
ESET published research concluding with high confidence that Okrum is operated by Ke3chang and that Okrum, Ketrican, and RoyalDNS activity observed after 2015 are linked to the same long-running actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 58 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcewelivesecurity.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcenccgroup.trust
Open sourcefireeye.com
Open sourceintezer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.