← Back to list

TryHackMe : Trooper Walkthrough

Room Link : [Trooper]

Abhinav Sharma · 2024-09-18 03:01 · 0 claps · 3.4 min read
#trooper #tryhackme #thm #walkthrough #tryhackme-walkthrough
Open on Medium ↗

TryHackMe : Trooper Walkthrough

Room Link : [Trooper]

Lab Description :

A multinational technology company has been the target of several cyber attacks in the past few months. The attackers have been successful in stealing sensitive intellectual property and causing disruptions to the company’s operations. A [threat advisory report] about similar attacks has been shared, and as a CTI analyst, your task is to identify the Tactics, Techniques, and Procedures (TTPs) being used by the Threat group and gather as much information as possible about their identity and motive. For this task, you will utilise the [OpenCTI] platform as well as the MITRE ATT&CK navigator, linked to the details below.

Assigned Tools :

Start the virtual machine by clicking on the green “Start Machine” button on the upper right section of this task. Give it about 7 minutes to fully load and use the credentials below to access the platforms via the AttackBox or VPN to conduct your investigations.

Apt X Report : [Link]

Report Citation:

Please note that the citation may contain spoilers about the contents of the challenge.

“Chen, Joey. (2020, May 12).Tropic Trooper’s USBferry Targets Air-Gapped Networks. TrendMicro. https://www.trendmicro.com/en_us/research/20/e/tropic-troopers-back-usbferry-attack-targets-air-gapped-environments.html

Walkthrough :

  1. What kind of phishing campaign does APT X use as part of their TTPs?

Just Read the APT X Report File Given in the room and you will find the answer.

Answer 1 : spear-phishing emails

  1. What is the name of the malware used by APT X?

Again go though the Report it has the answers :

Answer 2 : USBferry

  1. What is the malware’s STIX ID?

For this we need to head over to OpenCTI and Head over to Arsenal Section and then Search for USBferry!

Answer 3 : malware — 5d0ea014–1ce9–5d5c-bcc7-f625a07907d0

  1. With the use of a USB, what technique did APT X use for initial access?

For this lets head to MITRE Framework, and check out the section under “Initial Access”

Answer 4 : Replication through removable media

  1. What is the identity of APT X?

We can get this info from the Details section on the USBferry module of the OpenCTI :

Answer 5 : Tropic Trooper

  1. On OpenCTI, how many Attack Pattern techniques are associated with the APT?

For this we first need to Search For “Tropic Trooper” in Knowledge Module of the OpenCTI And then go to the Intrusion Set > Knowledge

Answer 6 : 39

  1. What is the name of the tool linked to the APT?

Just use the right side navigation to go to the tools section and click on it and you can now see it !

Answer 7 : BITSAdmin

  1. Load up the Navigator. What is the sub-technique used by the APT under Valid Accounts?

Answer 8 : Local Accounts

  1. Under what Tactics does the technique above fall?

Go to MITRE Framework > Home > Techniques > Enterprise And then we can search the the subtechnique’s ID we found in Navigator : [T1078]

Answer 9 : Initial Access, Persistence, Defense Evasion and Privilege Escalation

  1. What technique is the group known for using under the tactic Collection?

We could have also done this using OpenCTI, By Going to Knowledge > Tropic Trooper > Attack Pattern

Answer 10 : Automated Collection

Thats it ! Untill then ~


메타데이터
post_id
84fcddedcf4b
slug
tryhackme-trooper-walkthrough-84fcddedcf4b
url
https://medium.com/@abhinavsha077/tryhackme-trooper-walkthrough-84fcddedcf4b
canonical_url
https://medium.com/@abhinavsha077/tryhackme-trooper-walkthrough-84fcddedcf4b
author_url
https://medium.com/@abhinavsha077
status
ok
fetched_at
2026-08-24 21:15:08