Tropic Trooper targeted Chinese-speaking individuals in Taiwan and additional victims in South Korea and Japan with military-themed lure documents delivered in ZIP archives. The campaign used a trojanized SumatraPDF executable and a loader identified as TOSHIS to display an AUKUS-themed decoy PDF while decrypting and launching an AdaptixC2 Beacon in memory, marking a shift from the group’s earlier use of Cobalt Strike Beacon and Merlin Mythic. Researchers said the lures referenced US-UK and US-Australia nuclear submarine cooperation and were designed to blend into geopolitical themes likely to interest the targets.
The intrusion stood out for abusing trusted developer services for command and control and follow-on access. The customized AdaptixC2 implant used the GitHub repository cvaS23uchsahs/rss, relying on GitHub Issues and repository files for tasking, beaconing, and encrypted data exfiltration, while rapidly deleting issue artifacts to frustrate analysis. On selected victims, the operators then deployed VS Code tunnels for persistent interactive remote access. Infrastructure tied to the staging server also exposed EntryShell and a Cobalt Strike Beacon carrying watermark 520, reinforcing attribution to Tropic Trooper.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Itochu Cyber & Intelligence disclosed a Tropic Trooper intrusion in which the group compromised a target's home router, hijacked DNS settings, and delivered malware through what appeared to be a legitimate software update. The case showed the actor expanding beyond institutional targets to personal devices and individuals in Japan and the wider region.
Zscaler ThreatLabz published research detailing the campaign's lure documents, AdaptixC2 GitHub listener, VS Code tunnel usage, and attribution to Tropic Trooper. The disclosure highlighted the actor's pivot to open-source tooling and trusted platforms for command and control.
ThreatLabz linked the staging server and tooling to Tropic Trooper through infrastructure hosting EntryShell and a Cobalt Strike Beacon with watermark 520, alongside similarities to the TOSHIS loader. Based on these findings, researchers attributed the campaign to Tropic Trooper with high confidence.
After initial reconnaissance with the AdaptixC2 implant, the attackers deployed Visual Studio Code tunnels on selected victims to maintain interactive remote access. This reflected the group's use of trusted developer infrastructure as part of the intrusion chain.
The deployed AdaptixC2 implant used a customized GitHub-based listener tied to the repository cvaS23uchsahs/rss, abusing GitHub Issues and repository files for tasking, beaconing, and data exfiltration. Operators rapidly deleted beacon issues, likely to hinder analysis and forensic recovery.
The campaign used a trojanized SumatraPDF executable and a loader identified as TOSHIS to display an AUKUS-themed decoy PDF while decrypting and executing an AdaptixC2 Beacon in memory. Researchers noted this as a shift from earlier TOSHIS activity that used Cobalt Strike Beacon or Merlin Mythic.
ThreatLabz observed a Tropic Trooper campaign targeting Chinese-speaking individuals in Taiwan as well as victims in South Korea and Japan. The intrusion began with a ZIP archive containing Chinese-language, military-themed lure files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourcezscaler.com
Open sourcehitcon.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.