PULSE NAME
IOC - Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener
WHITE celestre 2026-04-23 Modified: 2026-05-23
29
IOCs
MEDIUM VOLUME
On March 12, 2026, Zscaler ThreatLabz discovered a malicious ZIP archive containing military-themed document lures targeting Chinese-speaking individuals. Our analysis of this sample uncovered a campaign leveraging a multi-stage attack chain where a trojanized SumatraPDF reader deploys an AdaptixC2 Beacon agent, ultimately leading to the download and abuse of Visual Studio (VS) Code tunnels for remote access. During our analysis, we observed that the threat actor likely targeted Chinese-speaking individuals in Taiwan, and individuals in South Korea and Japan. Based on the tactics, techniques, and procedures (TTPs) observed in this attack, ThreatLabz attributes this activity to Tropic Trooper (also known as Earth Centaur and Pirate Panda) with high confidence.
Indicators of Compromise (8 / 29 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2d7cc3646c287d6355def362916c6d26 2026-04-23
FileHash-MD5 3238d2f6b9ea9825eb61ae5e80e7365c 2026-04-23
FileHash-MD5 67fcf5c21474d314aa0b27b0ce8befb2 MD5 of 19e3c4df728e3e657cb9496cd4aaf69648470b63 2026-04-23
FileHash-MD5 71fa755b6ba012e1713c9101c7329f8d 2026-04-23
FileHash-MD5 89daa54fada8798c5f4e21738c8ea0b4 2026-04-23
FileHash-MD5 9a69b717ec4e8a35ae595aa6762d3c27 2026-04-23
FileHash-MD5 c620b4671a5715eec0e9f3b93e6532ba 2026-04-23
FileHash-MD5 e2dc48ef24da000b8fc1354fa31ca9ae 2026-04-23