Tropic Trooper (MITRE G0081; aka KeyBoy, Pirate Panda) is a Chinese-speaking espionage group long focused on East and Southeast Asia that, in 2023-2024, was observed conducting a prolonged intrusion against a Middle Eastern government entity.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Tropic Trooper has been active since at least 2011 and is tracked by MITRE as G0081 (aliases Pirate Panda, KeyBoy). It is assessed as a Chinese-speaking actor and has historically targeted government, healthcare, transportation and high-tech sectors in Taiwan, the Philippines and Hong Kong.
The group favors DLL search-order hijacking and sideloading from legitimate-but-vulnerable executables, web shells (including custom China Chopper variants), and loaders such as Crowdoor (named for its resemblance to ESET-documented SparrowDoor). It adapts quickly when tooling is blocked, pivoting to fresh loader variants to maintain access.
+43 more relationships — see the relationships browser.
MENA relevance emerged in September 2024, when Kaspersky's GReAT attributed, with high confidence, a year-long cyber-espionage intrusion against a governmental entity in the Middle East to Tropic Trooper. The operation ran from June 2023, deployed the Crowdoor loader and a newly developed China Chopper web-shell variant, and used new DLL search-order-hijacking implants. When defenses blocked the initial Crowdoor, the actors quickly switched to an unreported variant.
Confidence in the activity and the China-nexus assessment is high (Kaspersky, Trend Micro). Tropic Trooper's inclusion here reflects that specific Middle Eastern government targeting rather than a regional origin; no publicly disclosed 2025-2026 MENA campaign has followed, so last-confirmed activity is 2024.