logo

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

ID: 1c68205a-a09b-577f-8ecb-695ea7718e08

STIX ID: report--1c68205a-a09b-577f-8ecb-695ea7718e08

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Zscaler ThreatLabz discovered a Tropic Trooper campaign that distributes a trojanized SumatraPDF to show a decoy document while fetching encrypted shellcode to launch an AdaptixC2 Beacon. The attack chain uses a Xiangoop-derived loader (TOSHIS) to drop the beacon and lure, leverages GitHub as a C2 channel, and—after validating target value—installs VS Code and sets up VS Code tunnels for persistent remote access; staging infrastructure has also hosted Cobalt Strike and a custom backdoor (EntryShell).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.