Tropic Trooper uses GitHub and VS Code tunnels in a new campaign targeting East Asia
VPN Central [Unofficial]
April 25, 2026
A newly detailed cyberespionage campaign tied to Tropic Trooper shows the group shifting to newer tools and more covert infrastructure. Zscaler ThreatLabz says the attackers used a trojanized SumatraPDF executable, a custom AdaptixC2 beacon listener, GitHub as a command channel, and Visual Studio Code tunnels for follow-on remote access. The campaign targeted Chinese-speaking individuals in […]
The post Tropic Trooper uses GitHub and VS Code tunnels in a new campaign targeting East Asia appeared first on VPN Central.
Discussion in the ATmosphere