Skip to content
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets

Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets

First seen 24 Apr 2026, 09:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 25, 2026 at 08:47 UTC

On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing military-themed document lures, which included a trojanized version of the SumatraPDF reader. This trojan deploys an AdaptixC2 Beacon agent, facilitating remote access through Visual Studio Code tunnels. Concurrently, Darkreading reported Tropic Trooper's new tactics, including compromising home routers and utilizing spear-phishing techniques. The group has historically targeted government and military sectors but is now expanding its victimology. The recent campaigns indicate a shift in operational methods and tools, raising concerns about the group's evolving threat landscape. The full scope of the impact remains under investigation, with researchers noting the use of unconventional intrusion vectors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 166d ago How this analysis works

Timeline

2026-03-12
Zscaler discovers malicious ZIP archive targeting Chinese-speaking individuals.
2026-04-24
Zscaler and Darkreading report on Tropic Trooper's evolving tactics.
Date unknown
Itochu Cyber & Intelligence reports on router compromise incidents.

More articles in this cluster (5)

Following this threat?

Track The Tropic Trooper and AdaptixC2 Beacon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed