Threat Intelligence Tarot
Vol. II · 114
China
G0004★★★★★
risk 4/5
✦ The Vixen Courtier ✦
Ke3chang
Vixen Panda · APT15 · Mirage · Royal APT · Playful Dragon · Nickel
Foreign ministriesEnergyDefenseEuropean governmentsLatin American diplomatic targets
Active since ~2010 · Diplomatic espionage, Foreign policy intelligence
The Vixen Courtier slips between chancelleries the way rumor slips between dinners — never seen entering, somehow always there when the dispatch is read aloud.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆European Ministries of Foreign Affairs intrusions (2013)
- ◆Mirage, Ketrican, Okrum, and RoyalDNS malware families
- ◆UK government service provider supply-chain compromise (2017)
- ◆Microsoft DCU domain seizure operation (December 2021)
Defenses
- ▸Foreign ministry endpoint protection with high-fidelity EDRCIS Control 10 ↗
- ▸DNS sinkholing for known C2 domain patternsNIST CSF: DE.CM ↗
- ▸Vendor risk management for managed service providersNIST CSF: ID.SC ↗
- ▸Network segmentation isolating diplomatic correspondence systemsCIS Control 12 ↗
Reversed: Their Weakness
Microsoft's coordinated 42-domain takedown in late 2021 crippled this courtier's command infrastructure overnight. Coordinated civil action against C2 sprawl is its most consistent counter.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.