◇ SIGN IN
← all actors
apt

Tropic Trooper

activehigh confidence
APT / State-sponsored
Pirate PandaKeyBoyAPT23Earth Centaur
Attribution
Chinese-speaking espionage group (assessed China-nexus)
Origin
China (suspected)
First seen
2016
Last active
2024
Motivation
Espionage
Confidence
high
MENA targeting
Middle East (unnamed governmental entity focused on human rights studies)
Sectors
Government (human rights-focused entity)
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Middle East (unnamed governmental entity focused on human rights studies) (Government (human rights-focused entity) sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Tropic Trooper (MITRE G0081; aka KeyBoy, Pirate Panda) is a Chinese-speaking espionage group long focused on East and Southeast Asia that, in 2023-2024, was observed conducting a prolonged intrusion against a Middle Eastern government entity.

History

Tropic Trooper has been active since at least 2011 and is tracked by MITRE as G0081 (aliases Pirate Panda, KeyBoy). It is assessed as a Chinese-speaking actor and has historically targeted government, healthcare, transportation and high-tech sectors in Taiwan, the Philippines and Hong Kong.

The group favors DLL search-order hijacking and sideloading from legitimate-but-vulnerable executables, web shells (including custom China Chopper variants), and loaders such as Crowdoor (named for its resemblance to ESET-documented SparrowDoor). It adapts quickly when tooling is blocked, pivoting to fresh loader variants to maintain access.

MENA relevance emerged in September 2024, when Kaspersky's GReAT attributed, with high confidence, a year-long cyber-espionage intrusion against a governmental entity in the Middle East to Tropic Trooper. The operation ran from June 2023, deployed the Crowdoor loader and a newly developed China Chopper web-shell variant, and used new DLL search-order-hijacking implants. When defenses blocked the initial Crowdoor, the actors quickly switched to an unreported variant.

Confidence in the activity and the China-nexus assessment is high (Kaspersky, Trend Micro). Tropic Trooper's inclusion here reflects that specific Middle Eastern government targeting rather than a regional origin; no publicly disclosed 2025-2026 MENA campaign has followed, so last-confirmed activity is 2024.

Notable campaigns

2020
USBferry / air-gapped targeting
Trend Micro documented USB-based tooling used to reach air-gapped military and government networks in Asia.
2021
Earth Centaur (transportation/government)
Long-term intrusions against transportation and government bodies leveraging web shells and Exchange server exploitation.
2024
Middle East government intrusion
Kaspersky exposed a year-long espionage operation against a Middle Eastern government using Crowdoor and a new China Chopper web shell.