Tropic Trooper
MITRE ATT&CK: G0081 View on attack.mitre.org
Aliases: Pirate Panda, KeyBoy, PIRATE PANDA, Tropic Trooper, BRONZE HOBART, Red Orthrus, Earth Centaur
- First seen
- 2011-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- team
- Actor type
- nation-state
- Last IoC activity
- 2026-07-22 00:35:37
- Profile updated
- 2026-07-07 11:46:37
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical transportation-and-logistics technology-and-telecommunications
Targeted regions: country_code:tw country_code:ph country_code:hk
Context
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.
Detection coverage
- 7 YARA rules
- 613 Sigma rules
Malware & tools used
- Windows Service (attack-pattern)
- File Deletion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Process Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted Channel (attack-pattern)
- Web Protocols (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Template Injection (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Network Service Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Exfiltration over USB (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Web Shell (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Windows Command Shell (attack-pattern)
- Native API (attack-pattern)
- DLL (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Standard Encoding (attack-pattern)
- Local Accounts (attack-pattern)
Reports & references
- Mandiant — Apt Groups (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- blog.rapid7.com — Keyboy Targeted Attacks Against Vietnam And India (report)
- CrowdStrike — Rhetoric Foreshadows Cyber Activity In The South China Sea (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
- Trend Micro — Wp Operation Tropic Trooper (report)
- Trend Micro — Tropic Trooper New Strategy (report)
- Palo Alto Unit 42 — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
- blog.lookout.com — Titan Mobile Threat (report)
- MITRE ATT&CK — G0081 (report)
- secureworks.com — Bronze Hobart (report)
- Trend Micro — Collecting In The Dark Tropic Trooper Targets Transportation And Government Organizations (report)
- Trend Micro — Tech Brief Tropic Trooper S Back Usbferry Attack Targets Air Gapped Environments (report)
- researchcenter.paloaltonetworks.com — Unit42 Tropic Trooper Targets Taiwanese Government And Fossil Fuel Provider With Poison Ivy (report)
- CrowdStrike — On Demand Webcast Crowdstrike Experts On Covid 19 Cybersecurity Challenges And Recommendations (report)
External references
- mitre-attack — G0081
- Pirate Panda
- Tropic Trooper
- KeyBoy
- Crowdstrike Pirate Panda April 2020
- TrendMicro Tropic Trooper May 2020
- TrendMicro Tropic Trooper Mar 2018
- Unit 42 Tropic Trooper Nov 2016
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy