SunOrcal

First seen
2013-05-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:17:37

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

SunOrcal is a Remote Access Trojan (RAT) used primarily for cyber espionage activities targeting government and technology sectors. It has been associated with advanced persistent threat groups operating mainly in China and targeting entities in the United States.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Sunorcal_Auto (yara-rule)

Reports & references

  • researchcenter.paloaltonetworks.com — Unit42 New Malware With Ties To Sunorcal Discovered (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sunorcal (report)
  • pwc.blogs.com — Index (report)

External references