SunOrcal
- First seen
- 2013-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:17:37
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
SunOrcal is a Remote Access Trojan (RAT) used primarily for cyber espionage activities targeting government and technology sectors. It has been associated with advanced persistent threat groups operating mainly in China and targeting entities in the United States.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Sunorcal_Auto (yara-rule)
Reports & references
- researchcenter.paloaltonetworks.com — Unit42 New Malware With Ties To Sunorcal Discovered (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sunorcal (report)
- pwc.blogs.com — Index (report)