Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
    Cybersecurity

    Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

    adminBy adminApril 25, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 24, 2026Malware / Threat Intelligence

    Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access.

    Zscaler ThreatLabz, which discovered the campaign last month, has attributed it with high confidence to Tropic Trooper (aka APT23, Earth Centaur, KeyBoy, and Pirate Panda), a hacking group known for its targeting of various entities in Taiwan, Hong Kong, and the Philippines. It’s assessed to be active since at least 2011.

    “The threat actors created a custom AdaptixC2 Beacon listener, leveraging GitHub as their command-and-control (C2) platform,” security researcher Yin Hong Chang said in an analysis.

    It’s believed that Chinese-speaking individuals in Taiwan, and individuals in South Korea and Japan, are the targets of the campaign. The starting point of the attack is a ZIP archive containing military-themed document lures to launch the rogue version of SumatraPDF, which is then used to display a decoy PDF document, while simultaneously retrieving encrypted shellcode from a staging server to launch AdaptixC2 Beacon.

    To accomplish this, the backdoored SumatraPDF executable launches a slightly modified version of a loader codenamed TOSHIS, which is a variant of Xiangoop, a malware linked to Tropic Trooper, and has been used in the past to fetch next-stage payloads like Cobalt Strike Beacon or Merlin agent for the Mythic framework.

    The loader is responsible for activating the multi-stage attack, dropping both the lure document as a distraction mechanism and the AdaptixC2 Beacon agent in the background.The agent employs GitHub for C2, beaconing out to the attacker-controlled infrastructure to fetch tasks to be executed on the compromised host.

    The attack moves to the next stage only when the victim is deemed valuable, at which point the threat actor deploys VS Code and sets up VS Code tunnels for remote access. On select machines, the threat actor has been found to install alternative, trojanized applications, likely in an attemptto better camouflage their actions.

    What’s more, the staging server involved in the intrusion (“158.247.193[.]100”) has been observed hosting a Cobalt Strike Beacon and a custom backdoor called EntryShell, both of which have been put to use by Tropic Trooper in the past.

    “Similar to the TAOTH campaign, publicly available backdoors are used as payloads,” Zscaler said. “While Cobalt Strike Beacon and Mythic Merlin were previously used, the threat actor has now shifted to AdaptixC2.”

    AdaptixC2 Deploy GitHub SumatraPDF Trojanized Trooper Tropic
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleMeta is overhauling how you sign in, manage settings, and protect your accounts
    Next Article Your phone’s Bluetooth audio quality depends on one hidden setting nobody knows about
    admin
    • Website

    Related Posts

    Meta is overhauling how you sign in, manage settings, and protect your accounts

    April 25, 2026

    Microsoft rolls out revamped Windows Insider Program

    April 25, 2026

    US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

    April 25, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google’s Updates Push Search Further Into Task Completion

    April 25, 2026

    Your phone’s Bluetooth audio quality depends on one hidden setting nobody knows about

    April 25, 2026

    Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

    April 25, 2026

    Meta is overhauling how you sign in, manage settings, and protect your accounts

    April 25, 2026
    Categories
    • Blogging (68)
    • Cybersecurity (1,513)
    • Privacy & Online Earning (183)
    • SEO & Digital Marketing (928)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (246)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google’s Updates Push Search Further Into Task Completion

    April 25, 2026

    Your phone’s Bluetooth audio quality depends on one hidden setting nobody knows about

    April 25, 2026

    Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

    April 25, 2026
    Most Popular
    • Google’s Updates Push Search Further Into Task Completion
    • Your phone’s Bluetooth audio quality depends on one hidden setting nobody knows about
    • Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
    • Meta is overhauling how you sign in, manage settings, and protect your accounts
    • Android System WebView 147.0.7727.111 APK Download by Google LLC
    • Microsoft rolls out revamped Windows Insider Program
    • Google’s Nest Hub has no clue what time it is, and it’s messing with our heads
    • US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.