Tropic Trooper
Also tracked as Pirate Panda, KeyBoy
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.
- Documented techniques
- 40
- First seen
- 2011
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
initial access1
execution4
persistence4
discovery11
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1135 Network Share Discovery
- T1518 Software Discovery
- T1518.001 Security Software Discovery
- T1680 Local Storage Discovery
lateral movement1
collection1
command and control6
stealth10
- T1027.003 Steganography
- T1027.013 Encrypted/Encoded File
- T1036.005 Match Legitimate Resource Name or Location
- T1055.001 Dynamic-link Library Injection
- T1070.004 File Deletion
- T1078.003 Local Accounts
- T1140 Deobfuscate/Decode Files or Information
- T1221 Template Injection
- T1564.001 Hidden Files and Directories
- T1574.001 DLL
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.