Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.

Attribute Detail
ATT&CK ID G0004
Aliases APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon
Attribution China
Class state
Active since
ATT&CK entry created 2017-05-31
Techniques mapped 57

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1003.002 Security Account Manager
T1003.003 NTDS
T1003.004 LSA Secrets
T1005 Data from Local System
T1007 System Service Discovery
T1016 System Network Configuration Discovery
T1018 Remote System Discovery
T1020 Automated Exfiltration
T1021.002 SMB/Windows Admin Shares
T1027 Obfuscated Files or Information
T1033 System Owner/User Discovery

(First 12 of 57 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Mustang Panda — China-linked actor, same attribution class
  • Earth Lusca — China-linked actor, same attribution class
  • Salt Typhoon — China-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0004 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.