RoyalCli is a Windows backdoor used by the China-linked cyberespionage group APT15, also known as Ke3chang and Vixen Panda. It shares encryption and encoding routines with the group's older BS2005 backdoor. RoyalCli was identified during a May 2017 compromise of a UK government services provider, where attackers stole sensitive documents concerning government departments and military technology. It was deployed alongside BS2005 and RoyalDNS.
RoyalCli communicates with command-and-control servers over HTTP through Internet Explorer's IWebBrowser2 COM interface, providing a channel for attacker-directed commands on compromised hosts. This implementation causes command-and-control data to be cached on disk by Internet Explorer, leaving artifacts that can be recovered and decoded during forensic analysis. Persistence in the investigated deployment was configured externally through batch scripts that established registry-based execution at user logon, rather than through a self-contained installation mechanism. RoyalCli supports post-compromise access; a specific initial delivery mechanism has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used alongside BS2005 and RoyalDNS during the 2016–2017 compromise of a UK government contractor. The intrusion involved theft of government-related and military-technology material; individual backdoor capabilities are not detailed.
RoyalCli is a backdoor malware used by APT15 to maintain access and exfiltrate data from compromised networks.
Custom backdoor used by APT15 as part of its malware arsenal for covert access.
Backdoor in APT15's arsenal used to support access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.