Reviewed identity mapping approved on this date.
Ke3chang
G0004
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged for SPACEHOP Activity enabled China-nexus cyber threat…
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Loading CVEs, techniques, indicators, malware, victims, and activity...