RoyalCli is a Windows backdoor associated with the China-linked espionage group APT15, also tracked as Ke3chang and Vixen Panda. It was publicly identified during a 2017 intrusion against a service provider to the UK government and is assessed to be an evolution of APT15’s older BS2005 backdoor, reusing similar encryption and encoding routines. RoyalCli has been used in long-term intelligence collection operations targeting government-related and military-related information.
RoyalCli communicates with command-and-control infrastructure over HTTP by abusing Internet Explorer’s IWebBrowser2 COM interface, a technique also seen in BS2005. This approach blends malicious traffic with legitimate browser activity and can leave command data cached on disk by the browser process. The malware functions as a remote access backdoor enabling attacker-directed post-compromise activity. In operations where RoyalCli was deployed, APT15 conducted interactive command execution, reconnaissance with native Windows utilities, lateral movement through administrative shares and remote execution tooling, credential theft, keylogging, and data theft from enterprise platforms including email and SharePoint environments.
RoyalCli has been observed alongside other APT15 tooling such as RoyalDNS, BS2005, Okrum, Ketrum, and MirageFox. Persistence associated with the HTTP-based APT15 backdoors in this cluster was installed through batch-scripted mechanisms using Windows autorun functionality, likely to reduce behavioral detection. RoyalCli is part of a broader APT15 tradecraft pattern that combines custom backdoors with living-off-the-land techniques, stolen credentials, and sustained access to strategically significant organizations, particularly in government, diplomatic, and defense-related sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RoyalCli is a backdoor malware used by APT15 to maintain access and exfiltrate data from compromised networks.
Custom backdoor used by APT15 as part of its malware arsenal for covert access.
Custom APT15 implant/backdoor referenced as part of the group’s historical tooling.
Malware family mentioned only in a cited reference title.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.