Tropic Trooper

MITRE ATT&CK: G0081 View on attack.mitre.org

Aliases: Pirate Panda, KeyBoy, PIRATE PANDA, Tropic Trooper, BRONZE HOBART, Red Orthrus, Earth Centaur

First seen
2011-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
team
Actor type
nation-state
Last IoC activity
2026-07-22 00:35:37
Profile updated
2026-07-07 11:46:37

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical transportation-and-logistics technology-and-telecommunications

Targeted regions: country_code:tw country_code:ph country_code:hk

Context

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.

Detection coverage

  • 7 YARA rules
  • 613 Sigma rules

Malware & tools used

  • Windows Service (attack-pattern)
  • File Deletion (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Process Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted Channel (attack-pattern)
  • Web Protocols (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Template Injection (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration over USB (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Web Shell (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Native API (attack-pattern)
  • DLL (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Local Accounts (attack-pattern)

Reports & references

  • Mandiant — Apt Groups (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • blog.rapid7.com — Keyboy Targeted Attacks Against Vietnam And India (report)
  • CrowdStrike — Rhetoric Foreshadows Cyber Activity In The South China Sea (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
  • Trend Micro — Wp Operation Tropic Trooper (report)
  • Trend Micro — Tropic Trooper New Strategy (report)
  • Palo Alto Unit 42 — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
  • blog.lookout.com — Titan Mobile Threat (report)
  • MITRE ATT&CK — G0081 (report)
  • secureworks.com — Bronze Hobart (report)
  • Trend Micro — Collecting In The Dark Tropic Trooper Targets Transportation And Government Organizations (report)
  • Trend Micro — Tech Brief Tropic Trooper S Back Usbferry Attack Targets Air Gapped Environments (report)
  • researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
  • CrowdStrike — On Demand Webcast Crowdstrike Experts On Covid 19 Cybersecurity Challenges And Recommendations (report)

External references