Tropic Trooper Targets Middle East with New Web Shell

Red | Actor Report
Download PDF

Tropic Trooper, a Chinese-speaking APT group active since 2011, has expanded its targets from Asia to include Middle Eastern government entities, especially in human rights. In June 2024, they launched a new campaign involving the China Chopper web shell, exploiting Microsoft Exchange and Adobe ColdFusion vulnerabilities. The attack introduced the Crowdoor malware for network scanning and lateral movement, using DLL side-loading to evade defenses. Their growing sophistication indicates a focus on geopolitical espionage and regional security implications.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox