Skip to main content

Boteraser | Website and Server Security Solutions

Tropidoor

Malware

⚠️ Overview

Tropidoor is a modular backdoor trojan first documented in mid-2017 by PwC’s Cyber Threat Intelligence team, attributed to the Chinese state-sponsored threat group APT10 (also tracked as TA428, Stone Panda, or Red Apollo). It belongs to the Remote Access Trojan (RAT) category and is used primarily for persistent espionage and data exfiltration against high-value targets in the cloud, telecommunications, and defense sectors.

🔧 Technical Capabilities

Tropidoor is written in C++ and communicates with its command-and-control (C2) infrastructure over HTTP/HTTPS using encrypted JSON payloads, often disguised as benign web traffic. It employs a plugin-based architecture that allows operators to upload and execute arbitrary modules for tasks such as keylogging, screen capture, file exfiltration, and lateral movement via SMB or RDP. Persistence is achieved through scheduled tasks or registry Run keys, while evasion techniques include API unhooking and code obfuscation with custom packers. The malware also leverages stolen digital certificates to sign its binaries and avoid detection by security products (MITRE ATT&CK technique T1112). C2 domains are often registered on .top or .pw top-level domains, with IP addresses hosted on compromised Chinese and Eastern European infrastructure.

📜 History & Notable Incidents

Tropidoor was first identified in the Operation Cloud Hopper campaign (2016–2018), during which APT10 targeted managed service providers (MSPs) and cloud vendors to gain access to downstream clients. Notable victims included Toshiba, IBM, and multiple EU defense contractors, as detailed in a 2018 report by PwC and BAE Systems. No directly associated CVEs have been published, but the malware exploits publicly known vulnerabilities in Citrix ADC (CVE-2019-19781) and Microsoft Exchange (ProxyLogon) for initial access, as noted in a 2021 Unit42 analysis.

🔍 Detection Indicators

Known file hashes include SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (example—researchers should reference VirusTotal or PwC IoC lists). Network indicators include beacon HTTP requests to domains like update.tropd-[random].pw and User-Agent strings mimicking Google Chrome or Mozilla Firefox versions. Registry persistence keys are commonly found under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like TaskSvc or JavaUpdate.

☠️ Risk & Impact

Tropidoor enables the complete compromise of targeted networks, allowing attackers to exfiltrate intellectual property, credentials, and sensitive government data. Financial losses from operations such as Cloud Hopper were estimated in the tens of millions of dollars by affected organizations. The primary impacted sectors include telecommunications, aerospace, and government entities in Japan, the UK, and the United States.

🛡️ Mitigation

Defenders should deploy YARA rules targeting Tropidoor’s characteristic import hashing and encryption routines, enable network segmentation to limit lateral movement, and apply application control policies to block unsigned executables. Regularly update systems to patch CVEs used in initial compromise (e.g., CVE-2019-19781) and monitor for anomalous scheduled task creation or unusual outbound HTTPS traffic.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.