Tropic Trooper
Also reported as KeyBoy, Earth Centaur, Pirate Panda, APT23, PIRATE PANDA and 5 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1140 3 reports in ATT&CK
- T1057 2 reports in ATT&CK
- T1059.001 2 reports reports only
- T1059.003 2 reports in ATT&CK
- T1070.004 2 reports in ATT&CK
- T1071.001 2 reports in ATT&CK
- T1204.002 2 reports in ATT&CK
- T1218 2 reports reports only
- T1547.001 2 reports in ATT&CK
- T1574.001 2 reports in ATT&CK
Show all 69 techniques Show fewer
- T1583.001 2 reports reports only
- T1001.001 1 report reports only
- T1003.001 1 report reports only
- T1003.002 1 report reports only
- T1007 1 report reports only
- T1012 1 report reports only
- T1016 1 report in ATT&CK
- T1021.002 1 report reports only
- T1027.004 1 report reports only
- T1027.007 1 report reports only
- T1027.011 1 report reports only
- T1027.013 1 report in ATT&CK
- T1030 1 report reports only
- T1033 1 report in ATT&CK
- T1036.005 1 report in ATT&CK
- T1036.007 1 report reports only
- T1041 1 report reports only
- T1047 1 report reports only
- T1053.005 1 report reports only
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1059.005 1 report reports only
- T1070.006 1 report reports only
- T1071 1 report reports only
- T1072 1 report reports only
- T1082 1 report in ATT&CK
- T1087.001 1 report reports only
- T1087.002 1 report reports only
- T1090.001 1 report reports only
- T1095 1 report reports only
- T1112 1 report reports only
- T1113 1 report reports only
- T1115 1 report reports only
- T1124 1 report reports only
- T1127.001 1 report reports only
- T1132.001 1 report in ATT&CK
- T1190 1 report reports only
- T1204.001 1 report reports only
- T1221 1 report in ATT&CK
- T1543.003 1 report in ATT&CK
- T1555.003 1 report reports only
- T1556.002 1 report reports only
- T1564.001 1 report in ATT&CK
- T1564.003 1 report reports only
- T1564.006 1 report reports only
- T1566.001 1 report in ATT&CK
- T1566.002 1 report reports only
- T1568.002 1 report reports only
- T1573 1 report in ATT&CK
- T1573.001 1 report reports only
- T1574 1 report reports only
- T1583.004 1 report reports only
- T1585.002 1 report reports only
- T1585.003 1 report reports only
- T1587.001 1 report reports only
- T1588.001 1 report reports only
- T1588.002 1 report reports only
- T1595.002 1 report reports only
- T1622 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2006-3439
- CVE-2008-3431 KEV
- CVE-2008-4250 KEV
- CVE-2010-0817
- CVE-2010-2568 KEV
- CVE-2010-2729
- CVE-2010-2743
- CVE-2010-2772
- CVE-2010-3333 KEV
- CVE-2010-3338
Show all 165 CVEs Show fewer
- CVE-2010-3936
- CVE-2011-1264
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-3015
- CVE-2012-4792 KEV
- CVE-2013-3900 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-3567
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6352 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-0096
- CVE-2015-1641 KEV
- CVE-2015-1770 KEV
- CVE-2015-2545 KEV
- CVE-2015-5119 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0068
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-14100
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8464 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11511
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-8345
- CVE-2018-8346
- CVE-2018-8453 KEV ransomware
- CVE-2018-8570
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1188
- CVE-2019-1225
- CVE-2019-1280
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-16920 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0684
- CVE-2020-0688 KEV ransomware
- CVE-2020-0729
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1299
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1421
- CVE-2020-1472 KEV ransomware
- CVE-2020-15782
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-21551 KEV
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-24139
- CVE-2021-26855 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-31755 KEV
- CVE-2021-32305
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36958
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26352 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-49475
- CVE-2023-26360 KEV
- CVE-2023-2868 KEV
- CVE-2023-46747 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-28000
- CVE-2024-30051 KEV ransomware
- CVE-2024-32896 KEV
- CVE-2024-44000
- CVE-2024-45195 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bankshot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor StoneDrill (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
Tropic Trooper, Pirate Panda, APT 23, KeyBoy
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Tropic Trooper, Pirate Panda, APT 23, KeyBoy
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The KeyBoys are back in town
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
Show all 188 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor elf.wellmess (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor REvil (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PowGoop (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maze (Malware Family)
-
The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Rise of Earth Aughisky: Tracking the Campaigns Taidoor Started
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Collecting In the Dark- Tropic Trooper Targets Transportation and Government
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Collecting In the Dark- Tropic Trooper Targets Transportation and Government
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_jumping_the_air_gap_wp
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
Panda’s New Arsenal- Part 3 Smanager
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Panda’s New Arsenal- Part 3 Smanager
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper’s Back_ USBferry Attack Targets Air-gapped Environments - TrendLabs Security Intelligence Blog
-
Tropic Trooper’s Back- USBferry Attack Targets Air-gapped Environments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper’s Back- USBferry Attack Targets Air-gapped Environments
-
Tropic Trooper’s USBferry Targets Air-Gapped Networks
The original link failed its last check. Original publisher Detailsfor Tropic Trooper’s USBferry Targets Air-Gapped Networks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anomali Suspects that China-Backed APT Pirate Panda May Be Seeking Access to Vietnam Government Data Center
-
PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Windows Defender ATP device risk score exposes new cyberattack, drives Conditional access to protect networks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Delivery (Key)Boy
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper’s New Strategy
-
The original link failed its last check. Original publisher Detailsfor Tropic Trooper’s New Strategy
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper’s New Strategy
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
Tropic Trooper goes mobile with Titan surveillanceware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper goes mobile with Titan surveillanceware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The KeyBoys are back in town
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The KeyBoys are back in town
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy - Palo Alto Networks Blog
-
Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy
-
It's Parliamentary: KeyBoy and the targeting of the Tibetan Community
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor It's Parliamentary: KeyBoy and the targeting of the Tibetan Community
-
It’s Parliamentary - KeyBoy and the targeting of the Tibetan Community
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It’s Parliamentary - KeyBoy and the targeting of the Tibetan Community
-
Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Information Security: KeyBoy, Targeted Attacks ... | SecurityStreet
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Information Security: KeyBoy, Targeted Attacks ... | SecurityStreet
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
KeyBoy, Targeted Attacks against Vietnam and India
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor KeyBoy, Targeted Attacks against Vietnam and India
Newest first. Details opens the report in Explore.