Threat actor · all actors
Ke3changG0004 state
🇨🇳 CN
aka Ke3chang, APT15, Mirage, Vixen Panda, GREF, Playful Dragon, RoyalAPT, NICKEL, Nylon Typhoon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, G0004, Red Vulture, RIVER CASTLE
Last updated: 2026-08-21
About this actor
GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in their targeted attacks. Recently, they have been attributed to two active Android campaigns that distribute the BadBazaar malware through malicious apps on official and alternative app stores. GREF has targeted Android users, particularly Uyghurs and other Turkic ethnic minorities outside of China, using trojanized versions of popular messaging apps like Signal and Telegram.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 63 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-21236 | 5.8 | 7.8 | 0.0042 | 2026-02-10 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1003.004LSA Secrets ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1020Automated Exfiltration ↗T1021Remote Services ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.002Right-to-Left Override ↗T1036.005Match Legitimate Resource Name or Location ↗T1041Exfiltration Over C2 Channel ↗T1049System Network Connections Discovery ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1069Permission Groups Discovery ↗T1069.002Domain Groups ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1071.004DNS ↗T1078Valid Accounts ↗T1078.004Cloud Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1087.002Domain Account ↗T1105Ingress Tool Transfer ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1119Automated Collection ↗T1133External Remote Services ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1213Data from Information Repositories ↗T1213.002Sharepoint ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1558Steal or Forge Kerberos Tickets ↗T1558.001Golden Ticket ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1569System Services ↗T1569.002Service Execution ↗T1583Acquire Infrastructure ↗T1583.005Botnet ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1614System Location Discovery ↗T1614.001System Language Discovery ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 36 / 63 | 57% |
CM-6 | 33 / 63 | 52% |
CM-2 | 30 / 63 | 48% |
AC-3 | 29 / 63 | 46% |
AC-2 | 25 / 63 | 40% |
AC-6 | 25 / 63 | 40% |
CM-7 | 25 / 63 | 40% |
CA-7 | 23 / 63 | 37% |
SI-3 | 23 / 63 | 37% |
IA-2 | 22 / 63 | 35% |
AC-5 | 19 / 63 | 30% |
CM-5 | 19 / 63 | 30% |
SI-7 | 18 / 63 | 29% |
AC-4 | 14 / 63 | 22% |
IA-5 | 13 / 63 | 21% |
Co-occurring actors
- TA505 1 shared CVEs
- Threat Group-3390 1 shared CVEs
Similar actors
Similar TTPs
- Operation CuckooBees 0.41
- Chimera 0.36
- Operation Wocao 0.35
- FIN13 0.34
- MirrorFace 0.32
Overlapping CVEs
- TA505 1.00
- Threat Group-3390 0.20
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- APT12 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00