Ke3chang
MITRE: G0004Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
Ke3chang is an advanced persistent threat (APT) that has been active since at least 2014 and targets organizations in various industries, including government agencies, military contractors, and defense companies. It is believed to be linked to the Chinese People\'s Liberation Army (PLA). Ke3chang uses a variety of tactics such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to sensitive information and networks. The group has been responsible for several high-profile breaches including the 2014 OPM data breach that compromised personal information of over four million federal employees.
Techniques, tactics and practices:
Ke3chang uses a variety of tactics such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to sensitive information and networks. They also use social engineering techniques to trick employees into downloading malware or giving away their login credentials. Additionally, they have been known to conduct physical surveillance of targeted organizations before launching an attack. Ke3chang is a highly sophisticated threat actor that has demonstrated the ability to compromise even well-defended networks and systems.
