Trochilus
- First seen
- 2015-10-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:41:15
Targeted industries: government-and-public-sector education-and-nonprofits
Targeted regions: country_code:mm
Context
Trochilus is a remote access trojan (RAT) first identified in October 2015 when attackers used it to infect visitors of a Myanmar website. It was then used in a 2016 cyber-espionage campaign, dubbed "the Seven Pointed Dagger," managed by another group, "Group 27," who also uses the PlugX trojan. Trochilus is primarily spread via emails with a malicious .RAR attachment containing the malware. The trojan's functionality includes a shellcode extension, remote uninstall, a file manager, and the ability to download and execute, upload and execute, and access the system information. Once present on a system, Trochilus can move laterally in the network for better access. This trojan operates in memory only and does not write to the disk, helping it evade detection.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Trochilus_Rat_Auto (yara-rule)
Reports & references
- researchcenter.paloaltonetworks.com — Unit42 Trochilus Rat New Moonwind Rat Used Attack Thai Utility Organizations (report)
- securityaffairs.co — New Rat Trochilus (report)