Tropic Trooper (MITRE G0081; aka KeyBoy, Pirate Panda) is a Chinese-speaking espionage group long focused on East and Southeast Asia that, in 2023-2024, was observed conducting a prolonged intrusion against a Middle Eastern government entity.
Tropic Trooper has been active since at least 2011 and is tracked by MITRE as G0081 (aliases Pirate Panda, KeyBoy). It is assessed as a Chinese-speaking actor and has historically targeted government, healthcare, transportation and high-tech sectors in Taiwan, the Philippines and Hong Kong.
The group favors DLL search-order hijacking and sideloading from legitimate-but-vulnerable executables, web shells (including custom China Chopper variants), and loaders such as Crowdoor (named for its resemblance to ESET-documented SparrowDoor). It adapts quickly when tooling is blocked, pivoting to fresh loader variants to maintain access.
MENA relevance emerged in September 2024, when Kaspersky's GReAT attributed, with high confidence, a year-long cyber-espionage intrusion against a governmental entity in the Middle East to Tropic Trooper. The operation ran from June 2023, deployed the Crowdoor loader and a newly developed China Chopper web-shell variant, and used new DLL search-order-hijacking implants. When defenses blocked the initial Crowdoor, the actors quickly switched to an unreported variant.
Confidence in the activity and the China-nexus assessment is high (Kaspersky, Trend Micro). Tropic Trooper's inclusion here reflects that specific Middle Eastern government targeting rather than a regional origin; no publicly disclosed 2025-2026 MENA campaign has followed, so last-confirmed activity is 2024.