TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

The Hacker News

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

[email protected] (The Hacker News) · 2026-04-24 · Read original ↗

ATT&CK techniques detected

3 predictions
T1204.002Malicious File
97%
“is a zip archive containing military - themed document lures to launch the rogue version of sumatrapdf, which is then used to display a decoy pdf document, while simultaneously retrieving encrypted shellcode from a staging server to launch adaptixc2 beacon. to accomplish this, th…”
T1204.002Malicious File
87%
“tropic trooper uses trojanized sumatrapdf and github to deploy adaptixc2 chinese - speaking individuals are the target of a new campaign that uses a trojanized version of sumatrapdf reader to deploy the adaptixc2 beacon post - exploitation agent and ultimately facilitate the abus…”
T1572Protocol Tunneling
43%
“up vs code tunnels for remote access. on select machines, the threat actor has been found to install alternative, trojanized applications, likely in an attemptto better camouflage their actions. what ' s more, the staging server involved in the intrusion ( " 158. 247. 193 [. ] 10…”

Summary

Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access. Zscaler ThreatLabz, which discovered the campaign last month, has attributed it with high confidence to Tropic Trooper (aka