logo

Tropic Trooper: AdaptixC2 + Custom Beacon

ID: 88efd3df-2f50-5087-9574-675cf29732e6

STIX ID: report--88efd3df-2f50-5087-9574-675cf29732e6

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-05-01

...
...

ThreatLabz provides a technical analysis of a Tropic Trooper campaign that delivered a trojanized SumatraPDF (TOSHIS loader) which drops a decoy PDF while loading an AdaptixC2 Beacon configured to use a GitHub-based listener; the attackers used the beacon for reconnaissance and then deployed VS Code tunnels and other trojanized applications for remote access, with staging servers also hosting EntryShell and Cobalt Strike samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.