logo

APT23__2020__Tropic_Trooper_s_Back_USBferry_Attack_Targets_Air-gapped_Environments_-_TrendLabs_Security_Intelligence_Blog.pdf

ID: 31edae37-9580-4697-8210-7f230b85f67f

STIX ID: report--31edae37-9580-4697-8210-7f230b85f67f

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2020-05-14

Last Modified Date: 2020-05-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Trend Micro analyzes Tropic Trooper's USBferry campaign, a long-running targeted espionage operation that uses USB-based malware, steganography, backdoors and service-based persistence to infiltrate and exfiltrate sensitive documents from air-gapped and related networks in Taiwan, the Philippines and Hong Kong; the report explains multiple USBferry variants, supporting tools, communication methods, MITRE ATT&CK mappings, and provides mitigation recommendations and IoCs.