Trochilus

First seen
2015-10-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 15:41:15

Targeted industries: government-and-public-sector education-and-nonprofits

Targeted regions: country_code:mm

Context

Trochilus is a remote access trojan (RAT) first identified in October 2015 when attackers used it to infect visitors of a Myanmar website. It was then used in a 2016 cyber-espionage campaign, dubbed "the Seven Pointed Dagger," managed by another group, "Group 27," who also uses the PlugX trojan. Trochilus is primarily spread via emails with a malicious .RAR attachment containing the malware. The trojan's functionality includes a shellcode extension, remote uninstall, a file manager, and the ability to download and execute, upload and execute, and access the system information. Once present on a system, Trochilus can move laterally in the network for better access. This trojan operates in memory only and does not write to the disk, helping it evade detection.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Trochilus_Rat_Auto (yara-rule)

Reports & references

  • researchcenter.paloaltonetworks.com — Unit42 Trochilus Rat New Moonwind Rat Used Attack Thai Utility Organizations (report)
  • securityaffairs.co — New Rat Trochilus (report)

External references