logo

APT15__2019__ESET_Okrum_and_Ketrican.pdf

ID: a60e038a-3572-42d3-aa55-35a4078da625

STIX ID: report--a60e038a-3572-42d3-aa55-35a4078da625

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2019-07-16

Last Modified Date: 2019-07-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET provides a technical analysis of a previously undocumented backdoor named Okrum and related Ketrican and RoyalDNS malware, attributing activity from 2015–2019 to the Ke3chang (APT15) actor; the report details loaders/installers, anti-analysis techniques, C2 protocols, supported commands, auxiliary tools (credential dumping, keyloggers), campaign names, and extensive IOCs (SHA-1s, domains, mutexes) for victims including diplomatic missions in Slovakia, Belgium, Chile, Guatemala and Brazil.