Ke3chang
Also reported as Playful Dragon, Nylon Typhoon, APT15, Mirage, GREF and 26 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1036.005 3 reports in ATT&CK
- T1204.002 3 reports reports only
- T1027 2 reports in ATT&CK
- T1027.009 2 reports reports only
- T1041 2 reports in ATT&CK
- T1059.001 2 reports reports only
- T1071.001 2 reports in ATT&CK
- T1082 2 reports in ATT&CK
- T1132.001 2 reports reports only
- T1140 2 reports in ATT&CK
Show all 66 techniques Show fewer
- T1189 2 reports reports only
- T1509 2 reports reports only
- T1547.001 2 reports in ATT&CK
- T1566.001 2 reports reports only
- T1573.001 2 reports reports only
- T1583.001 2 reports reports only
- T1587.001 2 reports in ATT&CK
- T1608.001 2 reports reports only
- T1001.003 1 report reports only
- T1003 1 report reports only
- T1003.001 1 report in ATT&CK
- T1003.002 1 report in ATT&CK
- T1003.003 1 report in ATT&CK
- T1003.004 1 report in ATT&CK
- T1003.005 1 report reports only
- T1003.006 1 report reports only
- T1003.007 1 report reports only
- T1003.008 1 report reports only
- T1005 1 report in ATT&CK
- T1012 1 report reports only
- T1036.007 1 report reports only
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report in ATT&CK
- T1083 1 report in ATT&CK
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1106 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1207 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1218.014 1 report reports only
- T1418 1 report reports only
- T1422 1 report reports only
- T1426 1 report reports only
- T1430 1 report reports only
- T1437.001 1 report reports only
- T1497.001 1 report reports only
- T1533 1 report reports only
- T1553.002 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report reports only
- T1583.003 1 report reports only
- T1585.001 1 report reports only
- T1585.002 1 report reports only
- T1593.001 1 report reports only
- T1627.001 1 report reports only
- T1636.002 1 report reports only
- T1636.003 1 report reports only
- T1638 1 report reports only
- T1646 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3915
- CVE-2010-3916
- CVE-2011-1255
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
Show all 151 CVEs Show fewer
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0640 KEV
- CVE-2013-0707
- CVE-2013-0808
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-8651 KEV
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-15944 KEV
- CVE-2017-7269 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-16098
- CVE-2019-17100
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-27518 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2023-20867 KEV
- CVE-2023-2868 KEV
- CVE-2023-46747 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PLA Unit 61486
-
Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
-
MirageFox: APT15 Resurfaces With New Tools Based On Old Ones - Intezer
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor MirageFox: APT15 Resurfaces With New Tools Based On Old Ones - Intezer
-
APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 41 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
Show all 236 reports Show fewer
-
Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Chinese Playful Taurus Activity in Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Playful Taurus Activity in Iran
-
Precious Gemstones- The New Generation of Kerberos Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Precious Gemstones- The New Generation of Kerberos Attacks
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Gamaredon Group Understanding the Russian APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gamaredon Group Understanding the Russian APT
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
NICKEL targeting government organizations across Latin America and Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NICKEL targeting government organizations across Latin America and Europe
-
Complaint filed by Microsoft against NICKEL-APT15
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Complaint filed by Microsoft against NICKEL-APT15
-
Protecting people from recent cyberattacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Protecting people from recent cyberattacks
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
BackdoorDiplomacy- Upgrading from Quarian to Turian
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BackdoorDiplomacy- Upgrading from Quarian to Turian
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
Multiyear Surveillance Campaigns Discovered Targeting Uyghurs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multiyear Surveillance Campaigns Discovered Targeting Uyghurs
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 01/2020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor lookout-uyghur-malware-tr-us
-
Intezer - The Evolution of APT15's Codebase 2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Intezer - The Evolution of APT15's Codebase 2020
-
The Evolution of APT15’s Codebase 2020
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Evolution of APT15’s Codebase 2020
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT15
-
The original link failed its last check. Detailsfor APT15
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
Okrum- Ke3chang group targets diplomatic missions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Okrum- Ke3chang group targets diplomatic missions
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Okrum_and_Ketrican
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Into the Fog - The Return of ICEFOG APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
MirageFox: APT15 Resurfaces With New Tools Based On Old Ones - Intezer
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MirageFox: APT15 Resurfaces With New Tools Based On Old Ones - Intezer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal APT - APT15 Repository
-
New tools uncovered from hacking group APT15
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New tools uncovered from hacking group APT15
-
APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS
-
APT15 is alive and strong- An analysis of RoyalCli and RoyalDNS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT15 is alive and strong- An analysis of RoyalCli and RoyalDNS
-
An analysis of RoyalCli and RoyalDNS
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor An analysis of RoyalCli and RoyalDNS
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
Operation Ke3chang Resurfaces With New TidePool Malware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Ke3chang Resurfaces With New TidePool Malware
-
Operation Ke3chang Resurfaces With New TidePool Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ke3chang Resurfaces With New TidePool Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ke3chang Resurfaces With New TidePool Malware - Palo Alto Networks BlogPalo Alto Networks Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
Elite cyber crime group strikes back after attack by rival APT gang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elite cyber crime group strikes back after attack by rival APT gang
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Chinese hackers 'breach Australian media organisations' ahead of G20
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese hackers 'breach Australian media organisations' ahead of G20
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Putter Panda
-
OPERATION “KE3CHANG”-Targeted Attacks Against Ministries of Foreign Affairs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OPERATION “KE3CHANG”-Targeted Attacks Against Ministries of Foreign Affairs
-
Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
-
TDL4 - Purple Haze (Pihar) Variant - sample and analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TDL4 - Purple Haze (Pihar) Variant - sample and analysis
Newest first. Details opens the report in Explore.