logo

Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers

ID: c4dcae09-2e2f-4189-8ba4-7d8ff984689f

STIX ID: report--c4dcae09-2e2f-4189-8ba4-7d8ff984689f

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2015-04-24

Last Modified Date: 2015-04-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's analysis of "Operation Tropic Trooper" describes a targeted espionage campaign (active since ~2012) against Taiwanese and Philippine government and military targets using spear-phishing weaponized Office documents to exploit CVE-2010-3333 and CVE-2012-0158. The attackers employ a staged infection chain (TROJ_YAHOYAH downloader → TROJ_YAHAMAM service DLL → BKDR_YAHAMAM backdoor), steganography in image files, an accompanying rootkit (usb30.sys/RTKT_HIDEPORT) to hide communications, extensive C2 infrastructure and lateral-movement tools, and provide numerous IoCs and defensive recommendations.