New Tropic Trooper Attack Uses Custom Beacon Listener and VS Code Tunnels for Remote Access
ID: d7d44763-e63a-5e17-8c8e-5c22e1269b60
STIX ID: report--d7d44763-e63a-5e17-8c8e-5c22e1269b60
Feed Name: cybersecurityNews.com
**Executive Summary:** Tropic Trooper (aka Earth Centaur / Pirate Panda) ran a multi-stage cyberespionage campaign targeting Chinese-speaking users in Taiwan and victims in South Korea and Japan by distributing a trojanized SumatraPDF that displays a legitimate lure while installing an AdaptixC2 beacon; the beacon used GitHub Issues and file uploads (encrypted with RC4) as a covert C2 channel and the adversary later abused VS Code tunnels for interactive remote access. Zscaler ThreatLabz attributed the activity, identified additional tools on staging servers (Cobalt Strike Beacon with watermark “520”, EntryShell), and recommended blocking unexpected GitHub API traffic, application allowlisting, auditing VS Code tunnels, monitoring scheduled task creation, and hunting for ipinfo.io usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
