<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(zscaler.com) Tropic Trooper Deploys AdaptixC2 Beacon with Custom GitHub C2 Listener via Trojanized SumatraPDF]]></title><description><![CDATA[<p>(zscaler.com) Tropic Trooper Deploys AdaptixC2 Beacon with Custom GitHub C2 Listener via Trojanized SumatraPDF</p><p>Tropic Trooper (Earth Centaur/Pirate Panda) deploys AdaptixC2 Beacon via trojanized SumatraPDF in targeted cyber espionage campaign against Taiwan, South Korea, and Japan.</p><p>In brief - China-nexus APT Tropic Trooper targets Chinese-speaking individuals using military lures to deliver a trojanized SumatraPDF binary. The attack deploys AdaptixC2 Beacon with a custom GitHub C2 listener, followed by VS Code tunnel abuse for persistent access. EntryShell and CobaltStrike (watermark '520') reinforce attribution.</p><p>Technically - The trojanized SumatraPDF hijacks _security_init_cookie to execute TOSHIS loader, which resolves APIs via Adler-32 hashing and fetches second-stage shellcode from 158.247.193[.]100. Shellcode is decrypted using AES-128 CBC (key derived from MD5 of '424986c3a4fddcb6'). AdaptixC2 Beacon uses GitHub Issues API for C2, authenticating with a hardcoded PAT. RC4 session keys (16-byte, generated via RtlRandomEx(GetTickCount())) encrypt task results uploaded to GitHub. Post-compromise includes reconnaissance, scheduled task persistence, and VS Code tunnel deployment.</p><p>Source: <a href="https://www.zscaler.com/blogs/security-research/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener" rel="nofollow noopener"><span>https://www.</span><span>zscaler.com/blogs/security-res</span><span>earch/tropic-trooper-pivots-adaptixc2-and-custom-beacon-listener</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/494cdf90-d409-4b35-9486-7361dd60be13/zscaler.com-tropic-trooper-deploys-adaptixc2-beacon-with-custom-github-c2-listener-via-trojanized-sumatrapdf</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 07:51:23 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/494cdf90-d409-4b35-9486-7361dd60be13.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 22 Apr 2026 20:25:56 GMT</pubDate><ttl>60</ttl></channel></rss>