APT15 — APT Profile
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.Also tracked as
Ke3chang, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon
Tools & malware
- apk.badbazaar Mobile Malware
- win.bs2005 Backdoor
- win.exchange_tool Backdoor
- win.graphican Backdoor
- win.ketrican Backdoor
- win.ketrum Backdoor
- win.mirage Backdoor
- win.miragefox Backdoor
- win.okrum Backdoor
- win.plugx Backdoor
- win.royal_dns Backdoor
- win.royalcli Backdoor
- win.tidepool Backdoor
Vendor research
- How Microsoft names threat actors Microsoft
- NICKEL targeting government organizations across Latin America and Europe MSTIC
- MirageFox: APT15 Resurfaces With New Tools Based On Old Ones Rosenberg, J
- APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS Smallridge, R
- OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K
- OPERATION “KE3CHANG”: Targeted Attacks Against Ministries of Foreign Affairs Villeneuve, N., Bennett, J. T., Moran, N., Haq, T., Scott, M., & Geers, K