APT15 — APT Profile
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.Also tracked as
Ke3chang, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, Metushy, Social Network Team, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, G0004, Red Vulture, RIVER CASTLE
Tools & malware
- apk.badbazaar Mobile Malware
- win.bs2005 Backdoor
- win.exchange_tool Backdoor
- win.graphican Backdoor
- win.ketrican Backdoor
- win.ketrum Backdoor
- win.mirage Backdoor
- win.miragefox Backdoor
- win.okrum Backdoor
- win.plugx Backdoor
- win.royal_dns Backdoor
- win.royalcli Backdoor
- win.tidepool Backdoor
Vendor research
- OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K
- OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K
- MirageFox: APT15 Resurfaces With New Tools Based On Old Ones Rosenberg, J
- How Microsoft names threat actors Microsoft
- OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K
- APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS Smallridge, R
- NICKEL targeting government organizations across Latin America and Europe MSTIC
Countries linked to this actor
- Slovakia targets
- Jamaica targets
- Dominican Republic targets
- Honduras targets
- Guatemala targets