logo

Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets

ID: 0eb913c6-a26f-5988-84ac-4afaeb375815

STIX ID: report--0eb913c6-a26f-5988-84ac-4afaeb375815

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Tara Seals

...
...

Itochu and Zscaler researchers reported that Tropic Trooper has shifted tactics by leveraging a supply-chain compromise involving DNS hijacking of a victim's home router to serve trojanized updates (delivering a watermarked Cobalt Strike beacon). Investigations uncovered exposed S3 buckets with phishing decoys, new malware families and open-source loaders (e.g., Donut, DaveShell), Go-based RATs (Merlin Agent, Apollo Agent), custom backdoors (C6DOOR), and trojanized binaries, with campaigns targeting high-profile individuals across Japan, Taiwan, and South Korea and a list of IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.