EntryShell is a custom Windows backdoor associated with the China-linked espionage group Tropic Trooper, also tracked as Pirate Panda and KeyBoy. It has been observed as an in-memory payload delivered by Xiangoop loader variants through DLL side-loading, and it has also appeared alongside other Tropic Trooper tooling such as Cobalt Strike Beacon in staging infrastructure. Technical analysis has identified strong overlap between EntryShell and the older KeyBoy malware family, including matching embedded and encrypted strings tied to historical KeyBoy detections, leading to the assessment that EntryShell is an upgraded evolution of KeyBoy.
EntryShell is used in post-compromise operations to provide remote access and operator control on infected Windows systems. Its command structure and encrypted internal strings indicate backdoor functionality intended for hands-on intrusion activity. Reporting on Tropic Trooper campaigns places EntryShell within broader espionage operations involving deeper host investigation, remote control, and movement to additional endpoints or servers after initial access. The malware has been linked to campaigns targeting organizations and individuals in East Asia, including sectors such as government, healthcare, transportation, high technology, semiconductors, and rare-metal industries, with notable victim focus in Taiwan, Japan, South Korea, and China-related contexts.
Delivery of EntryShell has been observed indirectly through spearphishing-led intrusion chains and loader-based execution rather than as a standalone first-stage implant. In documented activity, Xiangoop loader families used email or SMS-based lures for initial compromise, then decrypted and deployed payloads such as EntryShell directly in memory. EntryShell’s design and deployment patterns are consistent with stealthy cyber-espionage tradecraft emphasizing staged execution, memory-resident payloading, and reuse of trusted or legitimate components for defense evasion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
分析の結果、今回発見したマルウェアであるEntryShellが、過去に使われたマルウェアKeyBoyとの間に非常に多くの点で共通していることを確認しました。
6 distinct techniques documented for this family, organized by ATT&CK tactic.
攻撃者はこのYaraルールの存在を認知しており、セキュリティ製品による検知を回避するために、EntryShell内で使用しているYaraルールで検知されそうな特徴的な文字列を暗号化していると考えられます。
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor hosted on the staging server and previously used by Tropic Trooper.
A custom backdoor observed on the staging server and previously used by Tropic Trooper.
An older known backdoor still used by Tropic Trooper.
A backdoor associated in the article with Tropic Trooper tooling and found on the staging server used in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.