APT23 is known for targeted spearphishing and USB-based data exfiltration against government entities.
Analyst brief
APT23 (also known as PIRATE PANDA) is a threat actor active since 2012, primarily targeting government, military, and administration entities. Its key TTPs include initial access via Spearphishing Attachment, use of malware like USBferry and ShadowPad, and data exfiltration methods such as Exfiltration over USB. Defenders should focus on securing email attachments, enforcing strict controls on USB devices, and monitoring network traffic for Encrypted Channel C2 communications.
APT23
PIRATE PANDAKeyBoyTropic Trooper
unknown
TrendMicro described Tropic Trooper in a 2015 report as: 'Taiwan and the Philippines have become the targets of an ongoing campaign called Operation TropicTrooper. Active since 2012, the attackers behind the campaign haveset their sights on the Taiwanese government as well as a number of companies in the heavy industry. The same campaign has also targeted key Philippine military agencies.'