logo

New Tropic Trooper Attack Uses Custom Beacon Listener and VS Code Tunnels for Remote Access

ID: d7d44763-e63a-5e17-8c8e-5c22e1269b60

STIX ID: report--d7d44763-e63a-5e17-8c8e-5c22e1269b60

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** Tropic Trooper (aka Earth Centaur / Pirate Panda) ran a multi-stage cyberespionage campaign targeting Chinese-speaking users in Taiwan and victims in South Korea and Japan by distributing a trojanized SumatraPDF that displays a legitimate lure while installing an AdaptixC2 beacon; the beacon used GitHub Issues and file uploads (encrypted with RC4) as a covert C2 channel and the adversary later abused VS Code tunnels for interactive remote access. Zscaler ThreatLabz attributed the activity, identified additional tools on staging servers (Cobalt Strike Beacon with watermark “520”, EntryShell), and recommended blocking unexpected GitHub API traffic, application allowlisting, auditing VS Code tunnels, monitoring scheduled task creation, and hunting for ipinfo.io usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.