Also known as: Pirate Panda, KeyBoy, KeyBoys, Tropic Trooper, BRONZE HOBART, G0081, Red Orthrus, Earth Centaur
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.(Citation: TrendMicro Tropic Trooper Mar 2018)(Citation: Unit 42 Tropic Trooper Nov 2016)(Citation: TrendMicro Tropic Trooper May 2020)
Southeast Asia
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Tropic Trooper, also known as Pirate Panda or KeyBoys, is a sophisticated cyber espionage group targeting government, healthcare, transportation, and high-tech industries primarily in Taiwan. The group has been active since at least 2011 and is known for using a variety of advanced persistence techniques and tools to achieve its objectives.
Goals & Targeting
Tropic Trooper's strategic objectives appear to be primarily centered on espionage, with a focus on gathering sensitive information from government and critical infrastructure sectors in Taiwan. The group's targeting profile suggests a regional focus in Southeast Asia, particularly against high-value targets such as transportation and healthcare organizations. This indicates that Tropic Trooter seeks to disrupt or gain unauthorized access to critical systems, possibly for political or strategic advantages.
Enhanced Description
Tropic Trooper is an unaffiliated threat group that has conducted targeted campaigns against organizations in Southeast Asia, including Taiwan, the Philippines, and Hong Kong. The group focuses on espionage activities, aiming to gather sensitive information from government agencies, healthcare institutions, and transportation sectors. Tropic Trooter's activities have been tracked since 2011, with recent activity noted as late as May 2020. The group is known for leveraging a range of tactics, including malicious files, encrypted communication channels, and file-less malware to maintain persistence and evade detection. Its operational capabilities include the use of tools such as KeyBoy, USBferry, PoisonIvy, and YAHOYAH.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Tropic Trooper has been linked to several campaigns targeting Southeast Asian organizations, with activity observed as recently as May 2020. The group's campaigns typically involve long-term access to systems, leveraging persistence techniques and encrypted communication channels. Notable victims have included government agencies and critical infrastructure entities in Taiwan. Tropic Trooter's modus operandi suggests a patient and methodical approach to maintaining access and avoiding detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Tropic Trooter's attributes is high, based on multiple intelligence sources and observed activities spanning over a decade. However, some details about the group's exact affiliations and complete list of campaigns remain uncertain due to limited public disclosure.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
40
Techniques
7
Tools
0
Campaigns
0
IOCs
0
Observed Data
9
Tactics