APT23__2018__Tropic_Trooper_s_New_Strategy.pdf
ID: 6ad39682-913c-4960-bd1b-ac591c03dfe6
STIX ID: report--6ad39682-913c-4960-bd1b-ac591c03dfe6
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2018-03-14
Last Modified Date: 2018-03-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro details Tropic Trooper (KeyBoy) targeted campaigns against Taiwanese, Philippine, and Hong Kong government and critical-sector organizations that use malicious Office documents exploiting CVE-2017-11882/CVE-2018-0802 to download MSI installers which deploy a loader (wab32res.dll/FakeRun) that DLL-hijacks sidebar.exe and injects the TClient backdoor (encrypted config, SSL C2). The report includes PDB-based attribution, decrypted backdoor configuration and C2 domains, multiple SHA-256 IoCs, analysis of TTPs (DLL hijacking, BITSadmin abuse, MSI delivery), and recommended mitigation and incident response practices.
