Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 22:31:23 UTC Home > List all groups > List all tools > List all groups using tool RoyalDNS Tool: RoyalDNS Names RoyalDNS Royal DNS Category Malware Type Backdoor, Tunneling Description RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'. Information Malpedia AlienVault OTX Last change to this tool card: 28 December 2022 Download this tool card in JSON format All groups using tool RoyalDNS Changed Name Country Observed APT groups Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon 2010-Oct 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b2226556-ff96-4e28-9459-371d3c79bda7 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=b2226556-ff96-4e28-9459-371d3c79bda7 Page 1 of 1