Tropic Trooper

Threat Actor updated 3 months ago (2024-11-29T14:25:04.716Z)
Download STIX
Preview STIX
Tropic Trooper, also known as KeyBoy and Pirate Panda, is an Advanced Persistent Threat (APT) group that has been active since 2011. This China-linked threat actor has been involved in numerous malicious activities, including espionage campaigns targeting Middle Eastern government entities and attacks on Taiwanese financial firms. The group's techniques include the use of the MQTT protocol for network communication with its Command and Control (C2), a method commonly used in Internet of Things (IoT) devices. Tropic Trooper's infrastructure has shown observable overlap with TA413 campaigns, suggesting possible collaboration or shared resources between the two groups. The group's malware has evolved over time, with Trend Micro noting that the 2013 versions of KeyBoy used the same algorithm for encoding configuration files as observed in Operation Tropic Trooper malware. Additionally, there have been cases where DLL hijacking attack chains, primarily utilized by state-sponsored actors like Lazarus Group and Tropic Trooper, were employed for evasion, persistence, and privilege escalation. Tropic Trooper was found to employ a technique that splits the malicious code across several stages, further complicating detection and mitigation efforts. Investigations into Tropic Trooper's activities have revealed more samples written by the group as well as third-party tools used in the post-exploitation phase. One notable event that led to deeper scrutiny of Tropic Trooper was the recurring detection of the China Chopper web shell. It was also discovered that the attackers attempted to launch a loader previously attributed to Tropic Trooper after failing to load it from a .bat file. Current assessments are reevaluating the relationship between Tropic Trooper and the FamousSparrow group, as some industry reports link these two groups together.
Description last updated: 2024-11-28T11:45:28.259Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
KeyBoy is a possible alias for Tropic Trooper. Keyboy is a malicious software (malware) that has been used for cyber espionage since 2011. It's primarily associated with the Advanced Persistent Threat (APT) group known as Tropic Trooper, also referred to as Pirate Panda and KeyBoy. This malware infiltrates systems through suspicious downloads, e
3
Pirate Panda is a possible alias for Tropic Trooper. Pirate Panda, also known as Tropic Trooper and Keyboy, is a recognized threat actor in the realm of cybersecurity. This group has been active since 2011 and has demonstrated malicious intent through various operations, primarily focused on targeting Tibetan infrastructure. The term 'threat actor' re
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Malware
Exploit
Espionage
Loader
Apt
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Tropic Trooper Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more