APT15 is alive and strong: An analysis of RoyalCli and RoyalDNS
released on 2018-03-10 @ 09:15:08 AM
In May 2017, NCC Groups Incident Response team reacted to an ongoing incident where our client, which provides a range of services to UK Government, suffered a network compromise involving the advanced persistent threat group APT15.
APT15 is also known as, Ke3chang, Mirage, Vixen Panda GREF and Playful Dragon.
A number of sensitive documents were stolen by the attackers during the incident and we believe APT15 was targeting information related to UK government departments and military technology.