TOSHIS is a Windows malware loader associated with the China-nexus threat actor Tropic Trooper and described as a variant of Xiangoop. It has been used in targeted intrusion campaigns against Chinese-speaking individuals, particularly in Taiwan, as well as victims in South Korea and Japan. In observed operations, TOSHIS was launched by a trojanized SumatraPDF executable delivered inside lure archives containing military-themed decoy documents. The rogue application displayed a benign-looking document to the victim while covertly retrieving and executing encrypted shellcode, after which TOSHIS deployed the lure document and a next-stage payload.
TOSHIS functions primarily as a staging component for post-compromise tooling. In the documented campaign, it delivered an AdaptixC2 Beacon agent that used a custom GitHub-based listener for command and control. Historical reporting also links TOSHIS to delivery of other follow-on payloads used by Tropic Trooper, including Cobalt Strike Beacon and Merlin agents. The broader intrusion workflow included selective follow-on activity against higher-value victims, such as abuse of Visual Studio Code tunnels for remote access and installation of additional trojanized applications for camouflage.
The malware is notable less for standalone espionage functionality than for its role in execution and payload delivery within a multi-stage infection chain. Its repeated association with Tropic Trooper and resemblance to tooling used in earlier campaigns make it a useful cluster indicator for that actor’s operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...an updated TOSHIS loader used by Tropic Trooper to deploy AdaptixC2 with custom GitHub listener.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The starting point of the attack is a ZIP archive containing military-themed document lures to launch the rogue version of SumatraPDF, which is then used to display a decoy PDF document, while simultaneously retrieving encrypted shellcode from a staging server to launch AdaptixC2 Beacon.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparative loader previously used by Tropic Trooper to deploy AdaptixC2.
A loader used to deploy the lure document and the AdaptixC2 Beacon agent; described as a variant of Xiangoop malware linked to Tropic Trooper.
A loader variant of Xiangoop used to activate a multi-stage attack and fetch next-stage payloads.
A loader previously linked to Tropic Trooper; the loader used in this campaign closely resembled it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.