All actors

Ke3chang

Also reported as Playful Dragon, Nylon Typhoon, APT15, Mirage, GREF and 26 other names. Linked to China by four sources.

Reports
236
Last reported
Known CVEs
151
Techniques in ATT&CK
46
Origin
China
ID
G0004
Merge evidence
52 alias matches

Reports per quarter

  1. 2012 Q1: 2 reports
  2. 2012 Q2: no reports
  3. 2012 Q3: no reports
  4. 2012 Q4: no reports
  5. 2013 Q1: 1 report
  6. 2013 Q2: no reports
  7. 2013 Q3: no reports
  8. 2013 Q4: 4 reports
  9. 2014 Q1: no reports
  10. 2014 Q2: 1 report
  11. 2014 Q3: no reports
  12. 2014 Q4: 2 reports
  13. 2015 Q1: 1 report
  14. 2015 Q2: 1 report
  15. 2015 Q3: 2 reports
  16. 2015 Q4: no reports
  17. 2016 Q1: no reports
  18. 2016 Q2: 7 reports
  19. 2016 Q3: 1 report
  20. 2016 Q4: no reports
  21. 2017 Q1: no reports
  22. 2017 Q2: 3 reports
  23. 2017 Q3: no reports
  24. 2017 Q4: 2 reports
  25. 2018 Q1: 9 reports
  26. 2018 Q2: 2 reports
  27. 2018 Q3: 2 reports
  28. 2018 Q4: no reports
  29. 2019 Q1: 2 reports
  30. 2019 Q2: 6 reports
  31. 2019 Q3: 6 reports
  32. 2019 Q4: 7 reports
  33. 2020 Q1: 8 reports
  34. 2020 Q2: 9 reports
  35. 2020 Q3: 9 reports
  36. 2020 Q4: 6 reports
  37. 2021 Q1: 11 reports
  38. 2021 Q2: 6 reports
  39. 2021 Q3: 8 reports
  40. 2021 Q4: 7 reports
  41. 2022 Q1: 7 reports
  42. 2022 Q2: 16 reports
  43. 2022 Q3: 7 reports
  44. 2022 Q4: 7 reports
  45. 2023 Q1: 11 reports
  46. 2023 Q2: 4 reports
  47. 2023 Q3: 8 reports
  48. 2023 Q4: 1 report
  49. 2024 Q1: 5 reports
  50. 2024 Q2: 8 reports
  51. 2024 Q3: 4 reports
  52. 2024 Q4: 1 report
  53. 2025 Q1: 7 reports
  54. 2025 Q2: 5 reports
  55. 2025 Q3: 1 report
  56. 2025 Q4: 2 reports
  57. 2026 Q1: 2 reports
  58. 2026 Q2: 15 reports
Dated reports, 2012 Q1 to 2026 Q2.

Techniques seen in the last two years

Show all 66 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 30 techniques Show fewer

CVEs named in reports

Show all 151 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. PLA Unit 61486

    date ORKL added it fromORKL

  2. MimiKatz (Malware Family)

    date ORKL added it fromORKL

Show all 236 reports Show fewer
  1. Chinese Playful Taurus Activity in Iran

    date in the title fromORKL

  2. Precious Gemstones- The New Generation of Kerberos Attacks

    date in the title fromORKL

  3. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  4. Gamaredon Group Understanding the Russian APT

    date in the title fromORKL

  5. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  6. Nickel

    Malpedia library date Notice of Pleadings fromORKLCCS '25 data

  7. Complaint filed by Microsoft against NICKEL-APT15

    date in the title fromORKL

  8. Protecting people from recent cyberattacks

    date in the title fromORKL

  9. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  10. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  11. BackdoorDiplomacy- Upgrading from Quarian to Turian

    date in the title fromORKL

  12. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  13. Analytics

    Malpedia library date fromORKL

  14. China cyber attacks- the current threat landscape

    date in the title fromORKL

  15. BfV Cyber-Brief Nr. 01/2020

    file creation date Bundesamt für Verfassungsschutz fromORKL

  16. lookout-uyghur-malware-tr-us

    Malpedia library date fromORKL

  17. Intezer - The Evolution of APT15's Codebase 2020

    file creation date fromORKL

  18. The Evolution of APT15’s Codebase 2020

    date in the title fromORKL

  19. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  20. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  21. APT15

    date in the title fromORKL

  22. APT15

    date in the CCS '25 data Intezer fromCCS '25 data

  23. Analytics

    Malpedia library date fromORKL

  24. Operation-Taskmasters-2019-eng

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  25. Okrum- Ke3chang group targets diplomatic missions

    date in the title fromORKL

  26. ESET_Okrum_and_Ketrican

    date in the CCS '25 data ESET fromORKLCCS '25 data

  27. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  28. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  29. Into the Fog - The Return of ICEFOG APT

    date in the title fromORKL

  30. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  31. rpt-mtrends-2019.pdf

    file creation date fromORKL

  32. rpt-mtrends-2019

    file creation date fromORKL

  33. MirageFox: APT15 Resurfaces With New Tools Based On Old Ones - Intezer

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  34. Royal APT - APT15 Repository

    date in the title fromORKL

  35. Royal APT - APT15 Repository

    date in the CCS '25 data NCC Group fromCCS '25 data

  36. New tools uncovered from hacking group APT15

    file creation date fromORKL

  37. APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS

    date in the CCS '25 data NCC Group fromORKLCCS '25 data

  38. Cyber Security Research

    Malpedia library date NCC Group fromORKLCCS '25 data

  39. An analysis of RoyalCli and RoyalDNS

    date in the CCS '25 data NCC Group fromORKLCCS '25 data

  40. Advanced Persistent Threat Groups

    date in the title fromORKL

  41. security_report_20160613.pdf

    Malpedia library date fromORKL

  42. Operation Ke3chang Resurfaces With New TidePool Malware

    date in the title fromORKL

  43. PowerPoint Presentation

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  44. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  45. Global Threat Intel Report

    Malpedia library date Crowdstrike fromORKL

  46. Putter Panda

    Malpedia library date Crowdstrike fromORKLCCS '25 data

  47. CrowdCasts Monthly: You Have an Adversary Problem

    Malpedia library date fromORKL

  48. TDL4 - Purple Haze (Pihar) Variant - sample and analysis

    date in the title fromORKL

Newest first. Details opens the report in Explore.