ATT&CKGroupsKe3chang

Ke3chang

G0004

Threat group.View on attack.mitre.org

About this group

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.

Techniques used46

Procedure examples46

TechniqueProcedure example
T1003.001
LSASS Memory

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.002
Security Account Manager

Ke3chang has dumped credentials, including by using gsecdump.

T1003.003
NTDS

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1003.004
LSA Secrets

Ke3chang has dumped credentials, including by using gsecdump.

T1005
Data from Local System

Ke3chang gathered information and files from local directories for exfiltration.

T1007
System Service Discovery

Ke3chang performs service discovery using net start commands.

T1016
System Network Configuration Discovery

Ke3chang has performed local network configuration discovery using ipconfig.

T1018
Remote System Discovery

Ke3chang has used network scanning and enumeration tools, including Ping.

T1020
Automated Exfiltration

Ke3chang has performed frequent and scheduled data exfiltration from compromised networks.

T1021.002
SMB/Windows Admin Shares

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1027
Obfuscated Files or Information

Ke3chang has used Base64-encoded shellcode strings.

T1033
System Owner/User Discovery

Ke3chang has used implants capable of collecting the signed-in username.

T1036.002
Right-to-Left Override

Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files.

T1036.005
Match Legitimate Resource Name or Location

Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`.

T1041
Exfiltration Over C2 Channel

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

View all 46 procedure examples

Software11

Campaigns1

References4

  1. APT15 Intezer June 2018 Open source
    Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.
  2. Mandiant Operation Ke3chang November 2014 Open source
    Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K. (2014). OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs. Retrieved November 12, 2014.
  3. Microsoft NICKEL December 2021 Open source
    MSTIC. (2021, December 6). NICKEL targeting government organizations across Latin America and Europe. Retrieved March 18, 2022.
  4. NCC Group APT15 Alive and Strong Open source
    Smallridge, R. (2018, March 10). APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS. Retrieved April 4, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.