logo

APT15__2018__An_analysis_of_RoyalCli_and_RoyalDNS.pdf

ID: 69ed6901-c2ca-4387-90c3-1f6768a9f3f5

STIX ID: report--69ed6901-c2ca-4387-90c3-1f6768a9f3f5

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2018-03-14

Last Modified Date: 2018-03-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
APT15 (aka Ke3chang) conducted a targeted intrusion against a UK government services provider; NCC Group analyzed new and known backdoors (RoyalCli, RoyalDNS, BS2005), recovered cached C2 commands and IOCs (hashes, domains), and documented the group's use of living-off-the-land techniques, credential theft (Mimikatz, golden tickets), stolen VPN certificates, and DNS TXT-based C2, resulting in exfiltration of sensitive documents.