Overview 220 indicators
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
| domain | 172 | G0004-domain.txt |
| ipv4 | 36 | G0004.json |
| url_path | 11 | G0004.json |
| url | 1 | G0004.json |
Techniques 46 ATT&CK
Open in ATT&CK Navigator → or download the layer (46 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1003.004 LSA Secrets
- T1005 Data from Local System
- T1007 System Service Discovery
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1020 Automated Exfiltration
- T1021.002 SMB/Windows Admin Shares
- T1027 Obfuscated Files or Information
- T1033 System Owner/User Discovery
- T1036.002 Right-to-Left Override
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1049 System Network Connections Discovery
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.003 Windows Command Shell
- T1069.002 Domain Groups
- T1071.001 Web Protocols
- T1071.004 DNS
- T1078 Valid Accounts
- T1078.004 Cloud Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1105 Ingress Tool Transfer
- T1114.002 Remote Email Collection
- T1119 Automated Collection
- T1133 External Remote Services
- T1140 Deobfuscate/Decode Files or Information
- T1190 Exploit Public-Facing Application
- T1213.002 Sharepoint
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1558.001 Golden Ticket
- T1560 Archive Collected Data
- T1560.001 Archive via Utility
- T1569.002 Service Execution
- T1583.005 Botnet
- T1587.001 Malware
- T1588.002 Tool
- T1614.001 System Language Discovery
Software 11
Principal sources 47 reports
Ranked by how many of this actor's indicators each report brought in.
- 45volexity.com/blog/2023/09/22/evilbamboo-targets-mobi…
- 45github.com/volexity/threat-intel/blob/main/2023/20…
- 45virustotal.com/gui/file/0fea799ce00c7d6f26ccb52a2ecbe6…
- 45virustotal.com/gui/file/1caf33e5cb45de1d3616bda85bea6c…
- 45virustotal.com/gui/file/f7132750db2a8ca8eb9e9e5a32377a…
- 45virustotal.com/gui/ip-address/45.154.12.132/relations
- 41blog.lookout.com/multiyear-surveillance-campaigns-discov…
- 41lookout.com/documents/threat-reports/us/lookout-uyg…
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 220 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
citizenlab.ca/2025/04/uyghur-language-software-hijack… · virustotal.com/gui/file/94a87dadeaac24bbc26c85d032b86a…
anar.gleeze.com gheyret.com gheyret.net tengri.ooguy.com uheyret.com wanar.gleeze.com -
github.com/PaloAltoNetworks/Unit42-timely-threat-i… · virustotal.com/gui/file/bfb44ed70b5096b9884245af952b97…
adobeonline.net update.adobeonline.net updateadobeappscom.adobeonline.net -
twitter.com/naumovax/status/1744741775661756421 · tria.ge/240109-rhyraacacq/behavioral1 · virustotal.com/gui/file/bdb84b702752c4065fa36f7c6f7038…
api--telegram.ru -
threatfox.abuse.ch/browse/tag/BadBazaar
domain 789aa654.top domain jkapp88.top domain k1-ai-jk.789aa654.top domain k3-ai-jk.jkapp88.top ipv4 154.212.147.129:443 -
twitter.com/naumovax/status/172042145649913054 · tria.ge/231103-l385vsfh7v · tria.ge/231103-nfveasbe23 · tria.ge/231005-2xj7jshg69 · virustotal.com/gui/file/f86420f5a92a39d92beef7279f219d…
domain api.telegram5.org domain api.telegramrc.com domain app.telegramrc.com domain down.telegramxo.com domain telegram5.org domain telegramrc.com domain telegramxo.com domain tgpc.telegramrc.com url_path /cc/adr/mobi url_path /cc/info/rep -
volexity.com/blog/2023/09/22/evilbamboo-targets-mobi… · github.com/volexity/threat-intel/blob/main/2023/20… · virustotal.com/gui/file/0fea799ce00c7d6f26ccb52a2ecbe6… · virustotal.com/gui/file/1caf33e5cb45de1d3616bda85bea6c… · virustotal.com/gui/file/f7132750db2a8ca8eb9e9e5a32377a… · virustotal.com/gui/ip-address/45.154.12.132/relations
domain adoptewer.com domain allwhatsapp.net domain bhvghg.com domain comeflxyr.com domain everydayinfo.top domain fgttgvh.com domain flygram.orgproxy1.signalplus.org domain fufijxgkg.com domain ggl.whoscaller.net domain goldplusapp.net domain graphicdata.net domain ignitetibet.net domain in7n.com domain jindjjdtc.com domain kmcuft.com domain o21q.com domain omarwhatsapp.org domain orgproxy1.signalplus.org domain thetubeplus.com domain tibetone.org domain tinmf.org domain tryhrwserf.com domain tubevideoplus.org domain upd.whoscaller.net domain uyghurdict.com domain uyghurinfo.net domain whoscaller.net ipv4 142.132.131.28:10433 ipv4 142.132.131.28:10434 ipv4 142.132.131.28:10435 ipv4 142.132.131.28:3251 ipv4 148.251.87.247:10433 ipv4 148.251.87.247:10434 ipv4 148.251.87.247:10435 ipv4 148.251.87.247:3251 ipv4 195.154.60.3:10433 ipv4 195.154.60.3:10434 ipv4 195.154.60.3:10435 ipv4 195.154.60.3:3251 ipv4 23.88.28.222:4432 ipv4 62.210.30.158:10433 ipv4 62.210.30.158:10434 ipv4 62.210.30.158:10435 ipv4 62.210.30.158:3251 ipv4 95.216.187.21:6656 -
threatfox.abuse.ch/browse/tag/BadBazaar
103.27.186.156:443 103.27.186.195:443 154.202.59.169:443 45.154.12.151:443 45.154.12.202:443 92.118.189.164:443 -
welivesecurity.com/en/eset-research/badbazaar-espionage-to…
domain flygram.org domain signalplus.org ipv4 148.251.87.245:4432 ipv4 185.239.227.14:3023 ipv4 217.163.29.84:7011 ipv4 45.133.238.92:6023 ipv4 45.154.12.132:4332 ipv4 45.63.89.238:1011 ipv4 62.210.28.116:2011 -
symantec-enterprise-blogs.security.com/blogs/threat-intelligence/flea-backdoor… · otx.alienvault.com/pulse/6492f2af01c58203dd0bcd3b
beltsymd.org cyclophilit.com cyprus-villas.org perusmartcity.com verisims.com -
twitter.com/malwrhunterteam/status/1616138902938746… · virustotal.com/gui/file/29f2616dc26a02216d8e17a52cc693… · virustotal.com/gui/file/100bb87b7dc3455b2aaef93753a44d…
ipv4 172.104.143.75:443 url http://172.104.143.75 -
twitter.com/malwrhunterteam/status/1616438178055094… · virustotal.com/gui/file/64ef2b23808484c9310408f7b530af…
106.75.99.101:8989 -
twitter.com/malwrhunterteam/status/1616438178055094… · virustotal.com/gui/file/45bcc4da58aacc018a36eb8a0b3125…
123.60.31.114:7005 -
twitter.com/malwrhunterteam/status/1616138902938746… · virustotal.com/gui/file/29f2616dc26a02216d8e17a52cc693… · virustotal.com/gui/file/100bb87b7dc3455b2aaef93753a44d…
172.104.143.75:8000 -
blog.lookout.com/multiyear-surveillance-campaigns-discov… · lookout.com/documents/threat-reports/us/lookout-uyg… · otx.alienvault.com/pulse/5efca5ec3da9c1ceace695fc
6006.secpert.com 6006.upupdate.cn amote-366.vicp.cc android.apps.us.to androidapps.duia.in androidapps.fvk.cc androidapps.home.hn.org androidapps.jetos.com androidapps.linkpc.net androidapps.myfirewall.org androidapps.nerdpol.ovh androidapps.npff.co androidapps.nsupdate.info androidapps.spdns.eu androidapps.spdns.org androidapps.tempors.com androidsapps.ml babyedu-online.com coco.wikaba.com cookedu-online.com englishedu-online.com googleanalyseservice.net googlleservice.com heartsys.dnsapi.info joke.upupdate.cn nortonservice.net phpyahoo.mrbasic.com s101.secpert.com s2.upupdate.cn ss903.w3.ezua.com ss904.w3.ezua.com symantecupdate.net sz.secpert.com tree.ddns.us turknews-online.com turkyedu-online.com umare.zyns.com vipapkdownload.com vipappdownload.com wephone.top youtube.dynamicdns.org.uk -
intezer.com/blog/research/the-evolution-of-apt15s-c… · otx.alienvault.com/pulse/5ec7f55daebc94b5857d69f1
menu.thehuguardian.com thehuguardian.com -
virustotal.com/gui/domain/edit.centrozhlan.com/relatio… · virustotal.com/gui/file/689f121c4a7309644c37141742abed…
centrozhlan.com -
twitter.com/in_threat/status/735472063247421440
goback.strangled.net -
/airliners.aspx?para= /dutchops.aspx?yf= /feeyo.aspx?who= /iTunes.aspx?e1= /paidai.aspx?e1= /playlist.aspx?yf= /pprune.aspx?yf= /shopmall.aspx?e1= /wikipedia.aspx?content= -
twitter.com/MeltX0R/status/1174442212412809216 · app.any.run/tasks/8d777de7-d51d-4c97-8e91-d0e54461f…
tick.ondemand-sport.com -
twitter.com/MeltX0R/status/1174069208709312512 · virustotal.com/gui/file/b5db7cfe22de56d292c83ea9ffa25f…
halimatoudi.com -
welivesecurity.com/2019/07/18/okrum-ke3chang-targets-diplo… · otx.alienvault.com/pulse/5d3040c20c143e436cc113d8
buy.babytoy-online.com center.nmsvillage.com chart.healthcare-internet.com compatsec.com control.mimepanel.org cv.livehams.com daily.huntereim.com dream.zepotac.com dsmanfacture.privatedns.org dyname.europemis.com finance.globaleducat.com forcan.hausblow.com grek.freetaxbar.com info.audioexp.com inicializacion.com item.amazonout.com items.babytoy-online.com items.burgermap.org login.allionhealth.com menorustru.com misiones.soportesisco.com newflow.babytoy-online.com press.premlist.com promise.miniaturizate.org rain.nmsvillage.com store.ufmsecret.org support.slovakmaps.com translate.europemis.com upcv.inciohali.com view.beleimprensa.org wind.deltimesweb.com www1.sanpaulostat.com -
nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2… · twitter.com/VK_Intel/status/976977927072985088
memozilla.org -
intezer.com/miragefox-apt15-resurfaces-with-new-too…
buy.healthcare-internet.com -
nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2… · twitter.com/VK_Intel/status/976977927072985088
andspurs.com cavanic9.net dnsapp.info log.autocount.org micakiz.wikaba.org news.memozilla.org ridingduck.com run.linodepower.com singa.linodepower.com video.memozilla.org zipcodeterm.com -
fireeye.com/blog/threat-research/2014/09/forced-to-…
allshell.net attoo1s.com battle.com.tw cdngoogle.com cisco-inc.net diablo-iii.mobi gefacebook.com googlemapsoftware.com kasparsky.net kocrmicrosoft.com microsoft.org.tw microsoftdomainadmin.com microsoftsp3.com microsoftupdate.ws mremote.biz msftncsl.com msnupdate.bz officescan.biz oprea.biz powershell.com.tw softwareupdatevmware.com square-enix.us updatamicrosoft.com windowsnine.net
Further reading 54
- attack.mitre.org/groups/G0004
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- research.nccgroup.com/2018/03/10/apt15-is-alive-and-strong-an…
- web.archive.org/web/20180615122133/https://www.intezer.…
- fireeye.com/content/dam/fireeye-www/global/en/curre…
- mandiant.com/resources/operation-ke3chang-targeted-a…
- microsoft.com/security/blog/2021/12/06/nickel-targeti…
- virustotal.com/gui/file/689f121c4a7309644c37141742abed…
- twitter.com/malwrhunterteam/status/1616438178055094…
- pastebin.com/qdDymcuy)
- nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2…
- twitter.com/VK_Intel/status/976977927072985088
- welivesecurity.com/2019/07/18/okrum-ke3chang-targets-diplo…
- virustotal.com/gui/file/64ef2b23808484c9310408f7b530af…
- twitter.com/malwrhunterteam/status/1616138902938746…
- otx.alienvault.com/pulse/5efca5ec3da9c1ceace695fc
- twitter.com/in_threat/status/735472063247421440
- otx.alienvault.com/pulse/5d3040c20c143e436cc113d8
- twitter.com/MeltX0R/status/1174069208709312512
- welivesecurity.com/en/eset-research/badbazaar-espionage-to…
- virustotal.com/gui/file/29f2616dc26a02216d8e17a52cc693…
- virustotal.com/gui/file/f86420f5a92a39d92beef7279f219d…
- virustotal.com/gui/file/f7132750db2a8ca8eb9e9e5a32377a…
- twitter.com/naumovax/status/172042145649913054
- virustotal.com/gui/file/1caf33e5cb45de1d3616bda85bea6c…
- fireeye.com/blog/threat-research/2014/09/forced-to-…
- tria.ge/231103-l385vsfh7v
- citizenlab.ca/2025/04/uyghur-language-software-hijack…
- twitter.com/MeltX0R/status/1174442212412809216
- intezer.com/blog/research/the-evolution-of-apt15s-c…
- tria.ge/231103-nfveasbe23
- github.com/PaloAltoNetworks/Unit42-timely-threat-i…
- app.any.run/tasks/8d777de7-d51d-4c97-8e91-d0e54461f…
- virustotal.com/gui/file/94a87dadeaac24bbc26c85d032b86a…
- threatfox.abuse.ch/browse/tag/BadBazaar
- otx.alienvault.com/pulse/6492f2af01c58203dd0bcd3b
- virustotal.com/gui/file/bfb44ed70b5096b9884245af952b97…
- twitter.com/naumovax/status/1744741775661756421
- tria.ge/240109-rhyraacacq/behavioral1
- virustotal.com/gui/domain/edit.centrozhlan.com/relatio…
14 more, and the report behind every indicator, in G0004.json.