Tropic Trooper – Campaign

Tropic Trooper employs a multi-stage attack flow:

  1. Initial Access: Exploiting vulnerabilities in public-facing applications (like Microsoft Exchange Server) or through spearphishing emails with malicious attachments.
  2. Persistence: Establishing persistent access using web shells (like “ByPassGodzilla”) and malware (like “Yahoyah” and “ChinaChopper”).
  3. Privilege Escalation: Utilizing DLL side-loading and exploiting system services to gain higher privileges.
  4. Lateral Movement: Moving laterally within the network using SMB shares and remote services.
  5. Data Exfiltration: Exfiltrating data to cloud storage or using other automated methods.