Trochilus is an open-source Windows remote access trojan implemented in C++ that has been publicly available since at least 2015 and has been repeatedly reused, modified, or adapted by multiple China-aligned espionage clusters. It functions as a backdoor for remote command execution and file transfer, and observed variants inject into legitimate Windows processes such as svchost.exe to operate in memory. Trochilus has also been delivered through DLL sideloading and multi-stage loader chains in which a legitimate executable loads a malicious DLL that decrypts or unpacks the final payload.
Trochilus is notable less as a single closed malware operation than as a reusable codebase that has served as the foundation for other malware families. RedLeaves was assessed to have been built by modifying Trochilus source code, and SprySOCKS was derived from Trochilus with substantial changes, including Linux implementations of Trochilus-like functionality and later Windows variants. Reporting has also tied customized Trochilus variants to Webworm and to activity associated with APT10 and APT31. In targeted intrusions, Trochilus-derived tooling has appeared against government, telecommunications, technology, defense, academia, media, managed service provider, aerospace, electric power, and other strategic sectors across Asia and elsewhere.
High-confidence capabilities directly associated with Trochilus include remote command execution, file download, and process injection. Delivery has been observed via DLL sideloading chains and embedded deployment within droppers, while the malware itself is a Windows-focused RAT whose source code has influenced later cross-platform backdoors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
baobeilong’s GitHub account shows a strong interest in Remote Access Trojans (RATs) including QuasarRAT and Trochilus, which baobeilong forked in 2015. JPCert reported in 2017 that Trochilus was used by APT10 as the basis for the RedLeaves malware.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
The URL https://chuanqiliebiao-1314[.]oss-cn-shanghai[.]aliyuncs[.]com/wp-content/plugins/Ssl-update.exe will download a dropper ... dubbed ‘DOUBLESTEP’ ... embedded with TROCHILUS.
Tooling-wise, APT31 initially used a number of malware families (RAWDOOR, Trochilus, EvilOSX, DropDoor/DropCat, etc.)...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA... Falcon Intelligence recently independently conducted detailed analysis of the RedLeaves malware... found it was directly sourced from Trochilus code
To cover the malicious traffic, the attackers registered C2 domains masquerading as normal AWS or AlibabaCloud domains... This cluster of activity has previously targeted entities... using malicious domains that masquerade as services such as Amazon Web Services and Microsoft Support Services.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the open-source RAT lineage from which SprySOCKS code derives.
An open-source Windows remote access tool that served as the basis for SprySOCKS, though SprySOCKS was sufficiently modified to be considered a distinct malware family.
A Windows remote access tool that serves as the codebase foundation for SprySOCKS and RedLeaves.
A Windows remote access trojan that served as the basis for SprySOCKS and has source code overlaps with RedLeaves.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.