APT15__2018__An_analysis_of_RoyalCli_and_RoyalDNS.pdf
ID: 69ed6901-c2ca-4387-90c3-1f6768a9f3f5
STIX ID: report--69ed6901-c2ca-4387-90c3-1f6768a9f3f5
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-03-14
Last Modified Date: 2018-03-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT15 (aka Ke3chang) conducted a targeted intrusion against a UK government services provider; NCC Group analyzed new and known backdoors (RoyalCli, RoyalDNS, BS2005), recovered cached C2 commands and IOCs (hashes, domains), and documented the group's use of living-off-the-land techniques, credential theft (Mimikatz, golden tickets), stolen VPN certificates, and DNS TXT-based C2, resulting in exfiltration of sensitive documents.
