Ke3chang — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
April 22, 2026
Last Seen
August 7, 2026

Related Threat Clusters

  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Guangdong Chanming Sells Botnet to PLA for Cyber Operations

    Guangdong Chanming, a covert Chinese company, has been linked to the sale of a spy botnet to the People's Liberation Army (PLA) and various hacking groups. This botnet serves as an anonymous relay network, facilitating…

    2 articles · Updated July 29, 2026
  • GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments

    Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…

    2 articles · Updated August 6, 2026
  • Cyber Adversaries Exploit File Enumeration and Data Collection Techniques

    Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…

    2 articles · Updated April 22, 2026

Recent Intelligence Reports

  • T1027 — attack.mitre.org · August 7, 2026
  • Guangdong Chanming Sold Spy Botnet to PLA and Nearly a Dozen Chinese Hacking Groups — Techtimes · July 29, 2026
  • External Remote Services — attack.mitre.org · June 3, 2026
  • T1005 — attack.mitre.org · April 22, 2026

CVSS v3.1 Breakdown