Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Tropic Trooper

Also known as: Pirate Panda, KeyBoy, KeyBoys, Tropic Trooper, BRONZE HOBART, G0081, Red Orthrus, Earth Centaur

Description

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.(Citation: TrendMicro Tropic Trooper Mar 2018)(Citation: Unit 42 Tropic Trooper Nov 2016)(Citation: TrendMicro Tropic Trooper May 2020)

TTP Summary

Southeast Asia

Goals & Targeting

Targeted Sectors

Government
Healthcare
Transportation

Targeted Countries / Regions

TW

AI Analysis

· 1 week ago

Executive Summary

Tropic Trooper, also known as Pirate Panda or KeyBoys, is a sophisticated cyber espionage group targeting government, healthcare, transportation, and high-tech industries primarily in Taiwan. The group has been active since at least 2011 and is known for using a variety of advanced persistence techniques and tools to achieve its objectives.

Goals & Targeting

Tropic Trooper's strategic objectives appear to be primarily centered on espionage, with a focus on gathering sensitive information from government and critical infrastructure sectors in Taiwan. The group's targeting profile suggests a regional focus in Southeast Asia, particularly against high-value targets such as transportation and healthcare organizations. This indicates that Tropic Trooter seeks to disrupt or gain unauthorized access to critical systems, possibly for political or strategic advantages.

Enhanced Description

Tropic Trooper is an unaffiliated threat group that has conducted targeted campaigns against organizations in Southeast Asia, including Taiwan, the Philippines, and Hong Kong. The group focuses on espionage activities, aiming to gather sensitive information from government agencies, healthcare institutions, and transportation sectors. Tropic Trooter's activities have been tracked since 2011, with recent activity noted as late as May 2020. The group is known for leveraging a range of tactics, including malicious files, encrypted communication channels, and file-less malware to maintain persistence and evade detection. Its operational capabilities include the use of tools such as KeyBoy, USBferry, PoisonIvy, and YAHOYAH.

Key Capabilities

  • Espionage activities targeting government and critical infrastructure
  • Deployment of file-less malware and malicious DLLs
  • Use of encrypted communication channels for C2
  • Leverage of removable media and USB-based attacks
  • Persistence techniques including registry run keys and startup folders

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Persistence
Defense Evasion
Discovery
Collection
Exfiltration
I.T. Infrastructure

ATT&CK Techniques

T1566.001
T1070.004
T1203
T1574.001
T1573
T1059.003
T1071.004
T1221

Software / Tooling

KeyBoy
USBferry
PoisonIvy
YAHOYAH
ShadowPad

Campaigns & Victims

Tropic Trooper has been linked to several campaigns targeting Southeast Asian organizations, with activity observed as recently as May 2020. The group's campaigns typically involve long-term access to systems, leveraging persistence techniques and encrypted communication channels. Notable victims have included government agencies and critical infrastructure entities in Taiwan. Tropic Trooter's modus operandi suggests a patient and methodical approach to maintaining access and avoiding detection.

IOC Patterns

  • Use of malicious DLLs and file-less malware
  • Encrypted or asymmetric cryptography for communication
  • USB-based attacks and persistence mechanisms
  • Registry modifications and startup folder entries
  • Network traffic anomalies using web protocols or DNS

Recommended Actions

  • Implement robust USB device policies and monitoring to detect suspicious activity.
  • Monitor for file-less malware activities and process injection techniques.
  • Use endpoint detection and response (EDR) solutions to identify malicious activities.
  • Regularly audit system configurations and remove unnecessary services or startup entries.
  • Enhance network monitoring for anomalies related to known Tropic Trooper TTPs.

Suggested Tags

espionage
APT
cyber-espionage
Taiwan
Southeast Asia
government-targeted

Confidence Assessment

Confidence in Tropic Trooter's attributes is high, based on multiple intelligence sources and observed activities spanning over a decade. However, some details about the group's exact affiliations and complete list of campaigns remain uncertain due to limited public disclosure.

ATT&CK Techniques

Command & Control
6 techniques
Discovery
11 techniques
Persistence
4 techniques
Stealth
10 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Crowdstrike Pirate Panda April 2020 — Busselen, M. (2020, April 7). On-demand Webcast: CrowdStrike Experts on COVID-19 Cybersecurity Challenges and Recommendations. Retrieved May 20, 2020.
  2. TrendMicro Tropic Trooper May 2020 — Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.
  3. TrendMicro Tropic Trooper Mar 2018 — Horejsi, J., et al. (2018, March 14). Tropic Trooper’s New Strategy. Retrieved November 9, 2018.
  4. Unit 42 Tropic Trooper Nov 2016 — Ray, V. (2016, November 22). Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy. Retrieved November 9, 2018.

Intel Summary

40

Techniques

7

Tools

0

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
cyber-espionage
Taiwan
Southeast Asia
government-targeted

Details

MITRE ID
G0081
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--56319646-eb6e-41fc-ae53-aadfa7adb924
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.