Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets
ID: 0eb913c6-a26f-5988-84ac-4afaeb375815
STIX ID: report--0eb913c6-a26f-5988-84ac-4afaeb375815
Feed Name: Dark Reading
Itochu and Zscaler researchers reported that Tropic Trooper has shifted tactics by leveraging a supply-chain compromise involving DNS hijacking of a victim's home router to serve trojanized updates (delivering a watermarked Cobalt Strike beacon). Investigations uncovered exposed S3 buckets with phishing decoys, new malware families and open-source loaders (e.g., Donut, DaveShell), Go-based RATs (Merlin Agent, Apollo Agent), custom backdoors (C6DOOR), and trojanized binaries, with campaigns targeting high-profile individuals across Japan, Taiwan, and South Korea and a list of IoCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
