Tropic Trooper, also known as KeyBoy and Pirate Panda, is an APT group active since 2011. The group has traditionally targeted government, healthcare, transportation, and high-tech sectors in Taiwan, the Philippines, and Hong Kong. Kaspersky assessed with high confidence that Tropic Trooper also conducted a persistent cyber-espionage campaign against a Middle Eastern government entity beginning in June 2023, indicating expansion beyond its traditional victimology; Kaspersky also observed a subset of related samples targeting a government entity in Malaysia. The reported motive in the Middle East intrusion was cyber espionage. The content attributes to Tropic Trooper a range of post-compromise discovery, persistence, collection, and command-and-control behaviors. Reported discovery activity includes searching for anti-virus software, detecting the target OS version and system volume information, monitoring file modified times, collecting host network topology with scripts, collecting information automatically via the USBferry attack, and using letmein to scan for saved usernames. Initial access and execution tradecraft includes luring victims into executing malware via malicious email attachments. For persistence, Tropic Trooper has created shortcuts in the Startup folder, installed a Windows service pointing to a malicious DLL dropped to disk, and created hidden directories under C:\ProgramData\Apple\Updates\ and C:\Users\Public\Documents\Flash. The group has used Windows command scripts, HTTP for C2, Base64 encoding to hide command strings delivered from C2, and shellcode with XOR decryption; it also decrypted image files containing payloads. In the Kaspersky-reported Middle East campaign, investigators found a compromised public Umbraco CMS server hosting a new .NET-based China Chopper web shell variant. The attackers used the server to execute commands and deploy post-exploitation tooling including Fscan, Swor, Neo-reGeorg, ByPassGodzilla, and batch scripts for lateral movement and evasion. Kaspersky identified DLL search-order hijacking loaders in c:\Users\Public\Music\data and c:\Windows\branding\data that attempted to load malicious datast.dll and later malicious VERSION.dll. The datast.dll loader decrypted next-stage shellcode using an RC4 variant with the hardcoded key fYTUdr643$3u. Newer Crowdoor-related loader variants from February 2024 used datastate.dll, datast.dll, and an encrypted payload file named WinStore. The Crowdoor payload established persistence by creating a Windows service named WinStore or, if that failed, by setting HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinStore; it also injected itself into colorcpl.exe and attempted to contact blog.techmersion[.]com over port 443. Kaspersky linked this activity to Tropic Trooper with high confidence based on shared RC4 keys, code similarity, overlapping tooling, and similarities to prior campaigns, while also noting overlap with the associated group FamousSparrow.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
...has exploited Office vulnerabilities such as CVE-2017-11882...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
In our telemetry, we noticed exploitation attempts of several CVEs (CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 in Microsoft Exchange, CVE-2023-26360 in Adobe ColdFusion). Therefore, we believe with moderate confidence that these web shells were dropped by exploiting an existing unpatched vulnerability.
3 more CVEs tied to this actor tracked in Mallory.
76 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor for exploitation activity related to abuse of the Windows Cloud Files API / cldapi.dll detection.
Conducting a sophisticated campaign targeting Chinese-speaking individuals using a trojanized SumatraPDF reader, deploying AdaptixC2 Beacon, abusing GitHub for command-and-control, and leveraging Microsoft Visual Studio Code tunnels for remote access.
Listed as a threat actor associated with exploitation and privilege-escalation detection coverage for Windows admin password changes by non-admin users.
Listed as a threat actor associated with exploitation for privilege escalation and Windows service persistence/installation in the detection annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.