Ke3chang is a China-linked espionage threat actor active in long-running cyber intrusion campaigns against government, diplomatic, and other strategic targets. The group is widely tracked under multiple aliases including APT15, Nickel, Vixen Panda, Playful Dragon, Playful Taurus, Mirage, Royal APT, Flea, Bronze Palace, Bronze Davenport, Bronze Idlewood, Nylon Typhoon, and Red Vulture. Reporting has also associated Ke3chang activity with PlugX-related intrusion clusters and custom backdoors used in targeted operations. The actor is known for developing and deploying custom malware to maintain persistence on victim networks. Observed tradecraft includes use of Registry Run-key persistence and batch-script-based installation mechanisms, command-line execution, and HTTP-based command-and-control communications, including malware families such as RoyalCli and BS2005. Ke3chang has conducted routine host and network reconnaissance after compromise, including process discovery with tasklist, operating system and host profiling with systeminfo, local network configuration discovery with ipconfig, and collection of signed-in username, computer name, and system language information. The group has also searched local files and directories, gathered data from victim systems, and exfiltrated compressed and encrypted archives through established backdoor channels. Ke3chang has been linked to the broader Chinese state-sponsored espionage ecosystem rather than financially motivated ransomware activity. Despite alias overlap in some datasets with unrelated ransomware names such as Royal or BlackSuit, the high-confidence characterization of Ke3chang is as a cyber-espionage intrusion set focused on stealthy access, persistence, victim profiling, and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
17 CVEs this actor has used in observed campaigns. 17 of them exploited in the wild.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
The weaponized document sent in phishing emails triggers the vulnerability outlined in CVE-2015-2545, which was first made public in September 2015... The TidePool malware is housed in an MHTML document which exploits CVE-2015-2545.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
The intruders gained initial access by chaining two critical Ivanti bugs, CVE-2024-8963 and CVE-2024-8190, days before they were publicly disclosed.
GREF was particularly active in the 2010 then it used different 0-day exploits, including CVE-2010-0806, CVE-2010-1297 and CVE-2010-2884 in its attacks.
12 more CVEs tied to this actor tracked in Mallory.
245 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a predecessor-linked ransomware group whose former members are believed to be connected to the Chaos ransomware operation.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.