Ke3chang
G00045 reportsaliases · Ke3chang · APT15 · Mirage · Vixen Panda · GREF · Playful Dragon · RoyalAPT · NICKEL · Nylon Typhoon
5
Reports
12
Techniques
7
Tactics
13
Countries
69%
Hunt coverage
9
Aliases
Analyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1053.005 (Scheduled Task), T1588.006 (Vulnerabilities).
- Primary targeting: US, BR, EG, RU.
- Steady activity: 2 report(s) in last 30d vs 1 prior (+100%).
- Recent movement: 7 new technique(s), 82 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 69% of 13 observed techniques (4 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
SteadyLast 30d: 2 vs 1 prior (+100%)· first reported 2026-04-23 · last 2026-09-07
0
7d
2
30d
4
90d
5
All
0.3
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1590.005T1059.007T1589.002T1593.003T1213.003T1546.016AML.T0095.000Dropped (90d+)
T1556.006Targeting gained
BRCADEEGILINKPUSTargeting lost
IRNew infrastructure
https://therecord.media/slovenia-cyberathttps://www.techradar.com/pro/security/2https://www.manifold.security/blog/ai-cohttps://www.forescout.com/blog/can-ai-crhttps://cybernews.com/security/cisa-flaghttps://hackread.com/jfrog-artifactory-vhttps://securityaffairs.com/198342/hackihttps://www.jamf.com/blog/contagious-int1ea83e4e4592b01e4acab63eb867bee5810f8e3b88eb05f710c09552941d6f56cbaaf0900a13f28e380f49adecec932c366515822d5ac1cc500711ef57a2e32eVulnerabilities in this actor's reporting · 3
- CVE-2026-82329KEV1 rpt
- CVE-2026-83548KEV1 rpt
- CVE-2026-83549KEV1 rpt
Overview
Analyst triage
Intelligence summary
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.(Citation: Mandiant Operation Ke3chang November 2014)(Citation: NCC Group APT15 Alive and Strong)(Citation: APT15 Intezer June 2018)(Citation: Microsoft NICKEL December 2021)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1589.001 · Credentialsconf 704
- T1053.005 · Scheduled Taskconf 602
- T1588.006 · Vulnerabilitiesconf 652
- T1204.002 · Malicious Fileconf 601
- T1059.001 · PowerShellconf 601
- T1556.006 · Multi-Factor Authenticationconf 601evidence: Critical minerals and cyber operations
- T1590.005 · IP Addressesconf 601
- T1059.007 · JavaScriptconf 601
- T1589.002 · Email Addressesconf 601
- T1593.003 · Code Repositoriesconf 601
- T1213.003 · Code Repositoriesconf 601
- T1546.016 · Installer Packagesconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|