ATT&CKGroupsTropic Trooper

Tropic Trooper

G0081

Threat group.View on attack.mitre.org

About this group

Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.

Techniques used40

Procedure examples40

TechniqueProcedure example
T1016
System Network Configuration Discovery

Tropic Trooper has used scripts to collect the host's network topology.

T1020
Automated Exfiltration

Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage.

T1027.003
Steganography

Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection.

T1027.013
Encrypted/Encoded File

Tropic Trooper has encrypted configuration files.

T1033
System Owner/User Discovery

Tropic Trooper used letmein to scan for saved usernames on the target system.

T1036.005
Match Legitimate Resource Name or Location

Tropic Trooper has hidden payloads in Flash directories and fake installer files.

T1046
Network Service Discovery

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.

T1049
System Network Connections Discovery

Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts.

T1052.001
Exfiltration over USB

Tropic Trooper has exfiltrated data using USB storage devices.

T1055.001
Dynamic-link Library Injection

Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe.

T1057
Process Discovery

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1059.003
Windows Command Shell

Tropic Trooper has used Windows command scripts.

T1070.004
File Deletion

Tropic Trooper has deleted dropper files on an infected system using command scripts.

T1071.001
Web Protocols

Tropic Trooper has used HTTP in communication with the C2.

T1071.004
DNS

Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol.

View all 40 procedure examples

Software6

Campaigns0

None recorded.

References3

  1. TrendMicro Tropic Trooper Mar 2018 Open source
    Horejsi, J., et al. (2018, March 14). Tropic Trooper’s New Strategy. Retrieved November 9, 2018.
  2. TrendMicro Tropic Trooper May 2020 Open source
    Chen, J.. (2020, May 12). Tropic Trooper’s Back: USBferry Attack Targets Air gapped Environments. Retrieved May 20, 2020.
  3. Unit 42 Tropic Trooper Nov 2016 Open source
    Ray, V. (2016, November 22). Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy. Retrieved November 9, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.