Home/Threat Actor/Tropic Trooper
Threat Actor

Tropic Trooper

tropic_trooper · china · active since 2011

Tropic Trooper (Pirate Panda / KeyBoy / Earth Centaur / BRONZE HOBART / APT23 / G0081) is a Chinese state-sponsored cyber- espionage actor active since at least 2011 with a defining mission focus on Taiwan, Hong Kong, and the Philippines aligned with PRC cross-strait and regional intelligence priorities; public-attribution baseline established by Trend Micro's 2015 'Operation Tropic Trooper' disclosure with subsequent vendor consolidation establishing KeyBoy (PWC), Pirate Panda (CrowdStrike), and Earth Centaur (Trend Micro 2021) as the same activity; targeting consistently emphasizes Taiwanese government ministries, heavy industry (fossil fuels, energy, manufacturing), transportation, healthcare, and high-tech sectors plus Hong Kong, Philippines, and Vietnam, with documented expansion to the Tibetan community (Citizen Lab November 2016), a Vietnamese government data center (Anomali April 2020), Middle Eastern government targets (Kaspersky December 2024), and individual users in Japan, Taiwan, and South Korea via home Wi-Fi router compromise (Itochu CTC Black Hat Asia 2025)

tradecraft hallmarks include sustained n-day exploitation via Office attachments and watering-hole compromises, the long-evolving KeyBoy / Yahoyah / TClient implant lineage, USBferry-based air-gap jumping (Trend Micro May 2020, one of the few publicly-documented Chinese- state air-gap operations), steganography in PNG images for payload delivery, the Nim-language Nimbda loader bundled with Chinese-underground greyware (Check Point June 2022), the Crowdoor loader and Umbraco CMS .NET-based compromise for Middle East operations (Kaspersky December 2024), and ChiserClient / SmileSvr / HTShell / Lilith RAT / Gh0st RAT second-stage implants delivered based on victim profiling.

china confidence: high 26 aliases MITRE ATT&CK G0081 ↗

Profile

Tropic Trooper (Pirate Panda / KeyBoy / Earth Centaur / BRONZE HOBART / APT23 / Iron Tropic / Red Orthrus / G0081) is a Chinese state-sponsored cyber-espionage actor active since at least 2011 with a defining mission focus on Taiwan, Hong Kong, the Philippines, and broader Southeast Asian targets aligned with PRC cross-strait and regional intelligence priorities. The cluster was first publicly documented by Trend Micro in 2015 under the name Operation Tropic Trooper, with subsequent vendor consolidation establishing KeyBoy (PWC), Pirate Panda (CrowdStrike), and Earth Centaur (Trend Micro's 2021 expansion) as the same underlying activity. PRC government affiliation is assessed based on Chinese-language artifacts in tooling, operating-hours alignment, infrastructure overlap with other Chinese-attributed clusters, and targeting consistency with PRC strategic interests.

specific MSS provincial bureau attribution is not publicly named in open-source reporting. Targeting consistently emphasizes Taiwan as the highest-priority target, government ministries (especially foreign affairs, defense, intelligence), heavy industry (fossil fuels, energy, manufacturing), transportation (aviation, shipping), healthcare, high-tech sectors, and increasingly individual targets, plus Hong Kong, the Philippines, and Vietnam. The November 2016 Citizen Lab disclosure documented expansion to Tibetan-community targeting, demonstrating cross-strait and broader anti-China- diaspora collection mission. December 2024 Kaspersky disclosure of Middle East government targeting represents the most significant recent geographic expansion. The 2025 Itochu CTC Black Hat Asia disclosure documented Tropic Trooper compromising victims' home Wi-Fi routers (DNS overwrite 'evil twin' attacks) and targeting individual users in Japan, Taiwan, and South Korea , a notable TTP evolution toward personal-device and consumer- network targeting. Tradecraft hallmarks: (a) sustained use of n-day exploits via Office document attachments and watering-hole compromises rather than zero-day development, the 2015 Trend Micro report title 'Relying on Tried-and-Tested Flaws' captures this pattern; (b) the long-evolving KeyBoy / Yahoyah / TClient implant lineage.

(c) air-gap-jumping via USBferry (Trend Micro May 2020) , one of the few publicly-documented Chinese state-actor air-gap operations.

(d) steganography in PNG images for payload delivery (Nimbda/Yahoyah)

(e) the Nim-language Nimbda loader bundled with Chinese-underground greyware (Check Point June 2022), unusual targeting vector for very specific victim populations.

(f) the Crowdoor loader and Umbraco CMS .NET-based compromise for Middle East government targeting (Kaspersky December 2024)

(g) China Chopper web-shell variants; (h) gh0st RAT and Poison Ivy commodity tooling alongside custom implants.

(i) Lilith RAT and SmileSvr / ChiserClient / HTShell second-stage implants delivered based on victim profiling. Tropic Trooper occupies a distinctive niche in the broader Chinese state-actor ecosystem: mid-sophistication but very long-running, with a clear regional-collection-mission profile distinct from the broader APT10 (MSP supply chain), APT40 (maritime), APT41 (dual espionage-criminal), and Naikon (ASEAN) patterns. Its sustained focus on Taiwan and the regional cross-strait intelligence mission, combined with willingness to experiment with unconventional TTPs (air-gap USB jumping, home router compromise, Chinese-underground greyware bundling), makes it operationally distinctive.

Aliases

26
tropic troopertropictrooperpirate pandapiratepandakeyboykey boyearth centaurearth_centaurbronze hobartbronze_hobartapt23apt 23apt-23iron tropiciron_tropicred orthrusred_orthrusoperation tropic trooperoperation_tropic_trooperusbferryusb_ferrynimbdatclientyahoyahmssg0081

Notable Campaigns

10
2025Home Router Compromise and Japanese Individual Targeting (Itochu CTC, Black Hat Asia 2025)
2023-2024Crowdoor Backdoor Against Middle Eastern Government (Kaspersky December 2024)
2022Nimbda Trojanized SMS Bomber (Check Point June 2022)
2021Earth Centaur Targeting Transportation Sector (Trend Micro December 2021)
2020USBferry Attack Targets Air-Gapped Environments (Trend Micro May 2020)
2020Pirate Panda Vietnam Government Data Center Targeting (Anomali April 2020)
2017The KeyBoys Are Back in Town (PWC February 2017)
2016Parliamentary KeyBoy and Tibetan Community Targeting (Citizen Lab November 2016)
2016Tropic Trooper Targets Taiwanese Government with Poison Ivy (Unit 42 November 2016)
2015Operation Tropic Trooper Initial Disclosure (Trend Micro 2015)

Attribution & Reporting

Attributed by
FBICISANSATaiwan NCSSTTaiwan TWNCERTPhilippines CICCHong Kong CSTCBUK NCSCFive EyesMicrosoftMandiantFireEyeGoogle Cloud Threat IntelligenceCrowdStrikeKaspersky GReATTrend MicroCheck Point ResearchCybereasonSentinelOnePalo Alto Networks Unit 42Cisco TalosSymantec / BroadcomESETCitizen LabAnomaliSecureWorksRecorded FutureInsikt GroupItochu CTCBitdefenderSOCRadar
Key reporting
reportTrend Micro: Operation Tropic Trooper, Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers (2015)
reportTrend Micro: Tropic Trooper's Back, USBferry Attack Targets Air-Gapped Environments (May 12, 2020)
reportTrend Micro: Earth Centaur, Tropic Trooper Targets Transportation and Government Organizations (December 2021)
reportPalo Alto Networks Unit 42: Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy (November 22, 2016)
reportCitizen Lab: It's Parliamentary KeyBoy and the Targeting of the Tibetan Community (November 17, 2016)
reportCheck Point Research: Never Truly Left, 7 Years of Scarlet Mimic's Mobile Surveillance Campaign (2022)
reportCheck Point Research: Tropic Trooper Spies Again, New Insights into Tropic Trooper Tools (June 21, 2022)
reportKaspersky GReAT: New Tropic Trooper Infection Chain Targeting Government Entities in the Middle East (December 2024)
reportKaspersky GReAT: Tropic Trooper Compromises Umbraco CMS Government Entity (December 2024)
reportAnomali: Pirate Panda May Be Seeking Access to Vietnam Government Data Center (April 30, 2020)
reportPWC: The KeyBoys Are Back in Town (February 11, 2017)
reportItochu CTC / Black Hat Asia 2025: Tropic Trooper Home Router Compromise (2025)
reportRecorded Future / Insikt Group: Chinese State-Sponsored Targeting of Taiwan
reportDark Reading: Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets (2025)
reportSOCRadar: Dark Web Profile, Tropic Trooper (APT23)
reportCouncil on Foreign Relations: Tropic Trooper Cyber Operations Tracker
reportEuRepoC: APT Profile, Tropic Trooper

Operational

State sponsor

People's Republic of China (PRC), assessed as state-sponsored by Trend Micro, Kaspersky, Check Point, Mandiant, Cybereason, and others based on Chinese-language artifacts in tooling, operating-hours alignment, infrastructure overlap with other Chinese-attributed clusters, and targeting consistently aligned with PRC strategic interests (Taiwan, Hong Kong, Philippines, anti-China-policy regional governments). Specific PRC government unit affiliation not publicly named in open-source attribution.

broadly assessed as MSS-aligned given the regional intelligence-collection mission profile.

Motivations
espionage, intelligence_gathering, geopolitical_collection, taiwan_focused_intelligence, regional_dominance, cross_strait_intelligence, tibetan_community_surveillance, air_gap_targeting, personal_device_targeting, dissident_tracking, dual_use_research_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)53/60 · 88%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)4/60 · 6%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin