Kaspersky reported that the Chinese-speaking APT group Tropic Trooper—also tracked as KeyBoy and Pirate Panda—ran a persistent cyber-espionage operation against a Middle Eastern government entity after compromising a public Umbraco CMS server. The intrusion began in June 2023 and continued into 2024, with the attackers deploying a new .NET-based China Chopper web shell variant to gain foothold and support follow-on activity on the exposed system.
Investigators said the operators then used post-exploitation tooling and DLL search-order hijacking loaders to deliver Crowdoor malware and maintain persistence, adapting their approach after security controls blocked an initial loader by introducing previously unreported VERSION.dll-based variants. Kaspersky linked the campaign to Tropic Trooper with high confidence based on code overlap, shared RC4 keys, tooling, and similarities to earlier operations, while noting some tradecraft overlap with FamousSparrow; the case also marks an apparent expansion of Tropic Trooper targeting beyond Taiwan, the Philippines, and Hong Kong to a Middle Eastern system publishing human-rights studies related to the Israel-Hamas conflict.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky reported that a persistent cyber-espionage campaign by Tropic Trooper against a Middle Eastern government entity began in June 2023. The intrusion started with compromise of a public Umbraco CMS server using a new .NET-based China Chopper web shell variant.
Kaspersky attributed the campaign to Tropic Trooper with high confidence based on code overlap, shared RC4 keys, tooling, and similarities to prior operations. Researchers also noted overlap with tradecraft associated with FamousSparrow.
During the intrusion, the attackers used post-exploitation tools and DLL search-order hijacking loaders to deliver Crowdoor malware and maintain persistence on the compromised environment. After an initial loader was blocked by security controls, they deployed previously unreported VERSION.dll-based variants to evade defenses.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.