CNChinaconfidence: 50G0004
APT15APT15
Also known as: VIXEN PANDA · Ke3Chang · Playful Dragon · Metushy · Lurid · Social Network Team · Royal APT · BRONZE PALACE · BRONZE DAVENPORT · BRONZE IDLEWOOD · NICKEL · G0004 · Red Vulture · Nylon Typhoon · Mirage · APT15
Origin
CN
Known aliases
16
Target sectors
1
Attribution
State-sponsored
Profile
APT15 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as VIXEN PANDA, Ke3Chang, Playful Dragon (and 12 more). Operational targeting focuses on the Government sector. Documented victim organisations include European Union, India, United Kingdom and 1 other named victims. Original record: This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
Aliases· 16
VIXEN PANDAKe3ChangPlayful DragonMetushyLuridSocial Network TeamRoyal APTBRONZE PALACEBRONZE DAVENPORTBRONZE IDLEWOODNICKELRed VultureNylon TyphoonMirageAPT15
Target sectors· 1
Government
Known victims· 4
- European Union
- India
- United Kingdom
- Germany
MITRE ATT&CK Group crosswalk
References
- https://www.fireeye.com/blog/threat-research/2014/09/forced-to-adapt-xslcmd-backdoor-now-on-os-x.html
- http://arstechnica.com/security/2015/04/elite-cyber-crime-group-strikes-back-after-attack-by-rival-apt-gang/
- https://github.com/nccgroup/Royal_APT
- https://www.cfr.org/interactive/cyber-operations/mirage
- https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-operation-ke3chang.pdf
- https://unit42.paloaltonetworks.com/operation-ke3chang-resurfaces-with-new-tidepool-malware/
- https://research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an-analysis-of-royalcli-and-royaldns/
- https://www.intezer.com/miragefox-apt15-resurfaces-with-new-tools-based-on-old-ones/
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.