As cited
Copy frozen at (site build).
threat intel
Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener
On March 12, 2026, Zscaler ThreatLabz identified a campaign by Tropic Trooper targeting Chinese-speaking individuals in Taiwan, South Korea, and Japan using military-themed document lures. The attack chain deployed a trojanized SumatraPDF reader containing the TOSHIS loader, which delivered an AdaptixC2 Beacon agent configured with a custom GitHub-based command-and-control listener. The threat actor used this foothold for reconnaissance and subsequently deployed Visual Studio Code tunnels for interactive remote access to victim machines.
Why it matters: Organizations in Taiwan, South Korea, and Japan, particularly those with Chinese-speaking staff, face active targeted intrusion risk from a nation-state actor; defenders should monitor for trojanized document delivery, TOSHIS loader signatures, and GitHub-based C2 communication patterns used by this group.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener
On March 12, 2026, Zscaler ThreatLabz identified a campaign by Tropic Trooper targeting Chinese-speaking individuals in Taiwan, South Korea, and Japan using military-themed document lures. The attack chain deployed a trojanized SumatraPDF reader containing the TOSHIS loader, which delivered an AdaptixC2 Beacon agent configured with a custom GitHub-based command-and-control listener. The threat actor used this foothold for reconnaissance and subsequently deployed Visual Studio Code tunnels for interactive remote access to victim machines.
Why it matters: Organizations in Taiwan, South Korea, and Japan, particularly those with Chinese-speaking staff, face active targeted intrusion risk from a nation-state actor; defenders should monitor for trojanized document delivery, TOSHIS loader signatures, and GitHub-based C2 communication patterns used by this group.
- Source published
- First seen by Cybersecurity Tracker