# MISP-Maltego Analysis Revisits Tropic Trooper TTPs

Published: 2019-10-27 · Severity: low
Canonical: https://vorant.io/reports/6a229c26-8667-55f1-9531-5a6f35b54113/misp-maltego-analysis-revisits-tropic-trooper-ttps

> A methodology piece shows how MISP and Maltego visualisations reveal discrepancies between a Cylance report and MITRE ATT&CK data on Tropic Trooper's techniques.

This article is a technical methodology piece from the MISP Project demonstrating how to use MISP threat-sharing data combined with the Maltego visualisation tool to better analyse and cross-reference MITRE ATT&CK-tagged threat intelligence. Using a September 2019 Cylance report on 'PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware' as a case study, the authors show that manual comparison of technique lists is error-prone due to human working-memory limits, and that graph visualisation surfaces a much larger discrepancy than initially assumed between the ATT&CK techniques documented in the report versus those MITRE associates with the actor.

The case study centers on the threat actor Tropic Trooper (MITRE ID G0081), linked to the PcShare backdoor and FakeNarrator malware. The analysis found only 5 techniques in common between the Cylance report and MITRE's documentation, with 13 techniques unique to MITRE and 11 unique to the report — far more divergence than a surface reading suggested. The piece attributes this gap to incomplete actor knowledge at documentation time, evolving actor TTPs, subjective tagging practices, and the generic nature of some ATT&CK techniques (partially addressed by MITRE's sub-techniques initiative).

Overall, this is an informational/analyst-tooling article rather than a report of active threat activity. It carries no new IOCs, vulnerabilities, or campaign disclosures, and primarily serves to promote best practices for CTI analysts using MISP and Maltego to reconcile and visualise ATT&CK-tagged threat data across sources.

## Mentioned in this report

- Threat actors: Tropic Trooper
- Malware: FakeNarrator, PcShare

Source reporting: https://www.misp-project.org/2019/10/27/visualising_common_patterns_attack.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6a229c26-8667-55f1-9531-5a6f35b54113/misp-maltego-analysis-revisits-tropic-trooper-ttps.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
