Skip to main content
Mallory
MalwareUsed by 1 actor

EntryShell

EntryShell is a custom backdoor associated with the China-linked threat actor Tropic Trooper (also tracked as APT23, Earth Centaur, KeyBoy, Pirate Panda, and Bronze Hobart). Reporting states it is an older, known Tropic Trooper tool and was observed hosted on staging server 158.247.193[.]100 alongside other Tropic Trooper-associated tooling, including Cobalt Strike Beacon carrying the group’s signature watermark "520." Its presence on the same infrastructure was cited as supporting attribution of related campaigns to Tropic Trooper. In the referenced activity, Tropic Trooper targeted Chinese-speaking individuals, primarily in Taiwan, as well as victims in Japan and South Korea, using military-themed lure documents and a trojanized SumatraPDF infection chain that deployed other payloads such as AdaptixC2 Beacon and abused VS Code tunnels for remote access. EntryShell itself is only described in the provided content as a custom backdoor previously used by Tropic Trooper; no additional high-confidence details on its infection vector, internal functionality, persistence, or command-and-control behavior are provided. One report notes the staging server hosted the EntryShell backdoor using the AES-128 ECB key "afkngaikfaf."

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Tropic Trooper

The staging server has also hosted Cobalt Strike Beacon and a custom backdoor, EntryShell, previously used by Tropic Trooper.

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1140Deobfuscate/Decode Files or InformationEvidence1
TacticStealth

TOSHIS loader then retrieves a second-stage shellcode from the same IP address, decrypts it using AES-128 CBC with WinCrypt cryptographic functions... The agent decodes its Base64-encoded contents... Each task in the queue is decrypted using the RC4 session key

T1105Ingress Tool TransferEvidence1

TOSHIS loader downloads the PDF decoy from 58.247.193[.]100... TOSHIS loader then retrieves a second-stage shellcode from the same IP address...

T1219Remote Access ToolsEvidence1

We decrypted these and found new malware... Merlin Agent and Apollo Agent, which are a Go-based remote access Trojans (RATs) that are part of the Mythics Agents open source C2 framework; and C6DOOR, a simple [custom] backdoor compiled with Go.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.