← Back to list

THM Trooper 2025 Walkthrough

Link to the room : https://tryhackme.com/r/room/trooper

Tomasz Kozlowski · 2025-01-06 01:19 · 0 claps · 3.2 min read
#apt-x #tropic-trooper #keyboy #usbferry #thm-writeup
Open on Medium ↗

THM Trooper 2025 Walkthrough

Link to the room : https://tryhackme.com/r/room/trooper

Tropic Trooper, also known as KeyBoy, is a cyber espionage group that has been active since at least 2011. This group primarily targets sectors such as government, healthcare, transportation, and high-tech industries in Taiwan, the Philippines, and Hong Kong. Here’s an overview of their operations and strategies:

Targeting and Tactics: Their campaigns focus on organizations that are likely to possess sensitive information. Tropic Trooper employs a variety of tactics for infiltration:

Social Engineering: They use spear-phishing emails with weaponized attachments, often exploiting known vulnerabilities in Microsoft Windows, particularly through exploit-laden Microsoft Office documents that appear to offer job vacancies or other enticing content to bait targets.

Malware Deployment: They’ve utilized malware like Poison Ivy, Yahoyah, and newer tools like USBferry for attacks on air-gapped environments. USBferry specifically targets physically isolated networks by using USB devices as a vector to breach secure systems, focusing on stealing defense, ocean, and ship-related documents.

Technological Adaptations: Over time, Tropic Trooper has shown adaptability by fine-tuning their tools:

New Behaviors: Recent analyses indicate that many of their tools now feature new behaviors, including changes in how they maintain persistence in compromised networks.

Exploits: They’ve notably used vulnerabilities like CVE-2012–0158 to deliver their payloads, demonstrating a reliance on both old and new exploits to infiltrate systems.

Recent Developments:

Middle Eastern Targeting: There’s been an expansion in their targeting, with recent campaigns against a governmental entity in the Middle East, particularly one involved in human rights studies, indicating a strategic shift. They’ve employed a variant of the China Chopper web shell and other tools like Crowdoor for these operations.

Advanced Techniques: Tropic Trooper has been noted for using DLL search-order hijacking to load malware, showcasing their capability to adapt to and overcome security measures.

Motivation and Attribution: While direct attribution to any state actor is complex, Tropic Trooper’s operations align with cyberespionage activities often associated with state-sponsored groups, particularly those with interests in the geopolitical dynamics of the regions they target.

Their activities underscore the need for robust cybersecurity measures in the regions they target, especially given their persistent and evolving attack vectors.

Questions below

1)What kind of phishing campaign does APT X use as part of their TTPs?

2)What is the name of the malware used by APT X?

3)What is the malware’s STIX ID?

4)With the use of a USB, what technique did APT X use for initial access?

5)What is the identity of APT X?

6)On OpenCTI, how many Attack Pattern techniques are associated with the APT?

7)What is the name of the tool linked to the APT?

First fail for Grok 2 — You need to use OPENCTI.

8)Load up the Navigator. What is the sub-technique used by the APT under Valid Accounts?

9)Under what Tactics does the technique above fall?

10)What technique is the group known for using under the tactic Collection?

https://attack.mitre.org/techniques/T1119/


메타데이터
post_id
fefb85c39d07
slug
thm-trooper-2025-walkthrough-fefb85c39d07
url
https://medium.com/@blockchainski2.0/thm-trooper-2025-walkthrough-fefb85c39d07
canonical_url
https://medium.com/@blockchainski2.0/thm-trooper-2025-walkthrough-fefb85c39d07
author_url
https://medium.com/@blockchainski2.0
status
ok
fetched_at
2026-06-26 21:52:29