THREAT_ACTOR · G0004
Ke3chang
Also known as: Ke3chang, APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon
Profile
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
MITRE ATT&CK ↗Techniques
46 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1003.003 NTDST1003.004 LSA SecretsT1005 Data from Local SystemT1007 System Service DiscoveryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1020 Automated ExfiltrationT1021.002 SMB/Windows Admin SharesT1027 Obfuscated Files or InformationT1033 System Owner/User DiscoveryT1036.002 Right-to-Left OverrideT1036.005 Match Legitimate Resource Name or LocationT1041 Exfiltration Over C2 ChannelT1049 System Network Connections DiscoveryT1056.001 KeyloggingT1057 Process DiscoveryT1059 Command and Scripting InterpreterT1059.003 Windows Command ShellT1069.002 Domain GroupsT1071.001 Web ProtocolsT1071.004 DNST1078 Valid AccountsT1078.004 Cloud AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1105 Ingress Tool TransferT1114.002 Remote Email CollectionT1119 Automated CollectionT1133 External Remote ServicesT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1213.002 SharepointT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1558.001 Golden TicketT1560 Archive Collected DataT1560.001 Archive via UtilityT1569.002 Service ExecutionT1583.005 BotnetT1587.001 MalwareT1588.002 ToolT1614.001 System Language Discovery
Software
11 malware/tools attributed to this actor.
MimikatzNetTasklistSysteminfoPingipconfignetstatspwebmemberMirageFoxOkrumNeoichor
Related corpus activity
10,316 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Ke3chang.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,316.