Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers
ID: c4dcae09-2e2f-4189-8ba4-7d8ff984689f
STIX ID: report--c4dcae09-2e2f-4189-8ba4-7d8ff984689f
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2015-04-24
Last Modified Date: 2015-04-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's analysis of "Operation Tropic Trooper" describes a targeted espionage campaign (active since ~2012) against Taiwanese and Philippine government and military targets using spear-phishing weaponized Office documents to exploit CVE-2010-3333 and CVE-2012-0158. The attackers employ a staged infection chain (TROJ_YAHOYAH downloader → TROJ_YAHAMAM service DLL → BKDR_YAHAMAM backdoor), steganography in image files, an accompanying rootkit (usb30.sys/RTKT_HIDEPORT) to hide communications, extensive C2 infrastructure and lateral-movement tools, and provide numerous IoCs and defensive recommendations.
