Talan.tech
LOWData BreachACTIVE

The Hacker News: Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

April 24, 2026

Incident Summary

A trojanized version of the SumatraPDF reader is being used in an attack targeting Chinese-speaking users. The malicious installer deploys malware and enables remote access by leveraging Microsoft VS Code tunnels. This matters because it can provide attackers persistent remote access to infected systems, even though the initial compromise is through the PDF reader rather than Microsoft Copilot itself. Limited public details are available on the scale of impacted users or whether Microsoft services were compromised.

Incident Details

Type
Data Breach
Severity
LOW
Status
ACTIVE
Date Occurred
April 24, 2026
Tags
#hackernews#security#breach