Tropic Trooper Hides C2 in GitHub Issues and Files
Tropic Trooper operators deploy a trojanised PDF reader to load AdaptixC2 malware in memory while secretly using GitHub repositories as a command-and-control channel for encrypted tasking and data exfiltration. The campaign combines decoy documents, AES-encrypted payloads, and post-compromise tools like VS Code tunnels to maintain stealthy access to infected systems.
Source: Zscaler
Read more: CyberSecBrief
















