Trochilus is an open-source Windows remote access trojan implemented in C++ and first observed in 2015. Its source code is publicly available on GitHub and has been adapted by multiple threat actors. It provides remote command execution and file upload, download, and execution capabilities, supporting post-compromise access and lateral movement.
Modified Trochilus variants used by Webworm execute in memory and inject into legitimate Windows processes. An analyzed deployment chain uses a legitimate executable to sideload a malicious DLL, followed by staged shellcode execution and in-memory unpacking of the RAT. Supporting loader components perform access-token theft and User Account Control bypasses. The final implant reads configuration data compressed with the Lempel–Ziv–Welch algorithm. Trochilus has also been embedded in DOUBLESTEP droppers used by the PRC-nexus actor UNC3569.
Trochilus has been used in attacks against Thai organizations and customized by Webworm, whose historical targets include government agencies and enterprises in IT services, aerospace, and electric power across Russia, Georgia, Mongolia, and other Asian countries. Its code also forms a foundation for the RedLeaves backdoor associated with APT10 and the distinct SprySOCKS family associated with Earth Lusca. The Linux adaptations and additional capabilities of these derivative families are not necessarily features of Trochilus itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
baobeilong’s GitHub account shows a strong interest in Remote Access Trojans (RATs) including QuasarRAT and Trochilus, which baobeilong forked in 2015. JPCert reported in 2017 that Trochilus was used by APT10 as the basis for the RedLeaves malware.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
The URL https://chuanqiliebiao-1314[.]oss-cn-shanghai[.]aliyuncs[.]com/wp-content/plugins/Ssl-update.exe will download a dropper ... dubbed ‘DOUBLESTEP’ ... embedded with TROCHILUS.
Tooling-wise, APT31 initially used a number of malware families (RAWDOOR, Trochilus, EvilOSX, DropDoor/DropCat, etc.)...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA... Falcon Intelligence recently independently conducted detailed analysis of the RedLeaves malware... found it was directly sourced from Trochilus code
To cover the malicious traffic, the attackers registered C2 domains masquerading as normal AWS or AlibabaCloud domains... This cluster of activity has previously targeted entities... using malicious domains that masquerade as services such as Amazon Web Services and Microsoft Support Services.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the open-source RAT lineage from which SprySOCKS code derives.
An open-source Windows remote access tool that served as the basis for SprySOCKS, though SprySOCKS was sufficiently modified to be considered a distinct malware family.
A Windows remote access tool that serves as the codebase foundation for SprySOCKS and RedLeaves.
A Windows remote access trojan that served as the basis for SprySOCKS and has source code overlaps with RedLeaves.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.