APT23__2020__Tropic_Trooper_s_Back_USBferry_Attack_Targets_Air-gapped_Environments_-_TrendLabs_Security_Intelligence_Blog.pdf
ID: 31edae37-9580-4697-8210-7f230b85f67f
STIX ID: report--31edae37-9580-4697-8210-7f230b85f67f
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2020-05-14
Last Modified Date: 2020-05-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Trend Micro analyzes Tropic Trooper's USBferry campaign, a long-running targeted espionage operation that uses USB-based malware, steganography, backdoors and service-based persistence to infiltrate and exfiltrate sensitive documents from air-gapped and related networks in Taiwan, the Philippines and Hong Kong; the report explains multiple USBferry variants, supporting tools, communication methods, MITRE ATT&CK mappings, and provides mitigation recommendations and IoCs.
