🇨🇳Tropic Trooper
🇨🇳 Tropic Trooper is a tracked threat actor in the Clankerusecase corpus. CN-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 40 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
40Techniques
0IOCs
About this actor (MITRE)
[Tropic Trooper](https://attack.mitre.org/groups/G0081) is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. [Tropic Trooper](https://attack.mitre.org/groups/G0081) focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.(Citation: TrendMicro Tropic Trooper Mar 2018)(Citation: Unit 42 Tropic Trooper Nov 2016)(Citation: TrendMicro Tropic Trooper May 2020)
Known aliases
Tropic TrooperPirate PandaKeyBoy
Top techniques
All other tracked techniques
T1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1049 · System Network Connections DiscoveryT1052.001 · Exfiltration over USBT1055.001 · Dynamic-link Library InjectionT1057 · Process DiscoveryT1059.003 · Windows Command ShellT1070.004 · File DeletionT1071.001 · Web ProtocolsT1071.004 · DNST1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1091 · Replication Through Removable MediaT1105 · Ingress Tool TransferT1106 · Native APIT1119 · Automated CollectionT1132.001 · Standard EncodingT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1203 · Exploitation for Client ExecutionT1204.002 · Malicious FileT1221 · Template InjectionT1505.003 · Web ShellT1518 · Software DiscoveryT1518.001 · Security Software DiscoveryT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1564.001 · Hidden Files and DirectoriesT1566.001 · Spearphishing AttachmentT1573 · Encrypted ChannelT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1680 · Local Storage Discovery