🌐Ke3chang
🌐 Ke3chang is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 46 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
46Techniques
0IOCs
About this actor (MITRE)
[Ke3chang](https://attack.mitre.org/groups/G0004) is a threat group attributed to actors operating out of China. [Ke3chang](https://attack.mitre.org/groups/G0004) has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.(Citation: Mandiant Operation Ke3chang November 2014)(Citation: NCC Group APT15 Alive and Strong)(Citation: APT15 Intezer June 2018)(Citation: Microsoft NICKEL December 2021)
Known aliases
Ke3changAPT15MirageVixen PandaGREFPlayful DragonRoyalAPTNICKELNylon Typhoon
All other tracked techniques
T1003.004 · LSA SecretsT1005 · Data from Local SystemT1007 · System Service DiscoveryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1020 · Automated ExfiltrationT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1033 · System Owner/User DiscoveryT1036.002 · Right-to-Left OverrideT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1049 · System Network Connections DiscoveryT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.003 · Windows Command ShellT1069.002 · Domain GroupsT1071.001 · Web ProtocolsT1071.004 · DNST1078 · Valid AccountsT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1105 · Ingress Tool TransferT1114.002 · Remote Email CollectionT1119 · Automated CollectionT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1213.002 · SharepointT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1558.001 · Golden TicketT1560 · Archive Collected DataT1560.001 · Archive via UtilityT1569.002 · Service ExecutionT1583.005 · BotnetT1587.001 · MalwareT1588.002 · ToolT1614.001 · System Language Discovery