news.mlab.sh
Threat intelligence
Threat actor

Ke3chang

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2010-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aerospace, Aviation, Chemical, Defense, Embassies, Energy, Government, High-Tech, Industrial, Manufacturing, Mining, Oil and gas, Telecommunications, Utilities
TLP
WHITE

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted several industries, including oil, government, military, and more.

Also known as

APT 15APT15BackdoorDiplomacyBronze DavenportBronze IdlewoodBronze PalaceCTG-9246FleaG0004G0135GREFKe3changMetushyMirageNickelNylon TyphoonPlayful DragonPlayful TaurusPurpleHazeRed VultureRoyal APTRoyalAPTSocial Network TeamVixen Panda

Vulnerabilities exploited

Tooling and malware

China ChopperMirageFoxNeoichorOkrumTurianipconfigMimikatzNBTscanNetnetstatPingQuasarRATspwebmemberSysteminfoTasklist

MITRE ATT&CK techniques

T1005 Data from Local SystemT1119 Automated CollectionT1560 Archive Collected DataT1095 Non-Application Layer ProtocolT1105 Ingress Tool TransferT1007 System Service DiscoveryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1120 Peripheral Device DiscoveryT1059 Command and Scripting InterpreterT1020 Automated ExfiltrationT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing ApplicationT1133 External Remote ServicesT1027 Obfuscated Files or InformationT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information

Coverage 1