www.zscaler.com Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
Article Content
- •Tropic Trooper is targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea.
- •The attack involves a trojanized SumatraPDF reader that deploys an AdaptixC2 Beacon agent.
- •The group is expanding its tactics to include router compromises and spear-phishing efforts.
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing military-themed document lures, which included a trojanized version of the SumatraPDF reader. This trojan deploys an AdaptixC2 Beacon agent, facilitating remote access through Visual Studio Code tunnels. Concurrently, Darkreading reported Tropic Trooper's new tactics, including compromising home routers and utilizing spear-phishing techniques. The group has historically targeted government and military sectors but is now expanding its victimology. The recent campaigns indicate a shift in operational methods and tools, raising concerns about the group's evolving threat landscape. The full scope of the impact remains under investigation, with researchers noting the use of unconventional intrusion vectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track The Tropic Trooper and AdaptixC2 Beacon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…