Tropic Trooper is a China-nexus advanced persistent threat group associated with cyberespionage operations. It is also known as KeyBoy. The group has been identified among notable Chinese intrusion sets operating in support of Chinese strategic interests, including intelligence collection against governments, finance, technology, and other strategically relevant sectors. Reported activity includes targeting Taiwanese financial institutions, consistent with broader China-aligned collection priorities in Asia. Tropic Trooper is part of the wider ecosystem of Chinese state-linked operators and contractors that conduct long-term intrusion campaigns with an emphasis on stealth, persistence, and strategic intelligence gathering rather than disruptive or criminal extortion outcomes. High-confidence reporting in the available material supports its inclusion as a China-nexus espionage actor, but does not provide sufficient direct detail here on specific sub-groups, malware families, or a fuller victimology beyond the financial-sector targeting in Taiwan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tropic Trooper is a China-nexus threat actor known for targeting financial, manufacturing, and semiconductor industries, especially in Taiwan and Southeast Asia.
Active in the region; generally described as less technically advanced and focused on regional government/military targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.