Tropic Trooper spies on government entities in the Middle East
ID: 44f936ee-de0e-52a5-984e-7a01c38a59f6
STIX ID: report--44f936ee-de0e-52a5-984e-7a01c38a59f6
Feed Name: Securelist by Kaspersky
Kaspersky researchers report a 2023–2024 Tropic Trooper campaign that compromised an Umbraco CMS using a new .NET China Chopper web shell, dropped post-exploitation tools (Fscan, Swor, Neo-reGeorg), and attempted DLL search-order hijacking to load Crowdoor loaders that deploy Cobalt Strike; multiple samples, IOCs (hashes, file paths, IPs/domains) and exploited CVEs are included, with high-confidence attribution to Tropic Trooper targeting government entities in the Middle East and Malaysia for espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
