created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Ke3chang
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0004 |
| Aliases | APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon |
| Attribution | China |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2017-05-31 |
| Techniques mapped | 57 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1003.002 |
Security Account Manager |
T1003.003 |
NTDS |
T1003.004 |
LSA Secrets |
T1005 |
Data from Local System |
T1007 |
System Service Discovery |
T1016 |
System Network Configuration Discovery |
T1018 |
Remote System Discovery |
T1020 |
Automated Exfiltration |
T1021.002 |
SMB/Windows Admin Shares |
T1027 |
Obfuscated Files or Information |
T1033 |
System Owner/User Discovery |
(First 12 of 57 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Mustang Panda — China-linked actor, same attribution class
- Earth Lusca — China-linked actor, same attribution class
- Salt Typhoon — China-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0004 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.