Trochilus is an open-source Windows remote access trojan written in C++ that has been publicly available since at least 2015 and has been repeatedly reused, modified, or incorporated by multiple China-aligned intrusion sets. It functions as a backdoor/RAT framework and has served both as a directly deployed implant and as source material for derivative malware including RedLeaves and SprySOCKS. Security reporting has also linked customized Trochilus variants to activity by groups such as Webworm, APT31, and clusters overlapping with Earth Lusca or FishMonger through downstream tooling derived from its codebase.
On Windows, Trochilus and modified variants have been observed using multi-stage loader chains, DLL sideloading, in-memory unpacking, and process injection into legitimate processes such as svchost.exe to establish covert remote access. Documented capabilities include remote command execution, file download and upload, execution of additional payloads, system and process interaction, and use as a general-purpose foothold for follow-on operations. Customized deployments have also incorporated privilege-related tradecraft such as token theft and UAC bypass in surrounding loader stages.
Trochilus has been used in espionage-oriented campaigns targeting government and enterprise victims, including sectors such as IT services, aerospace, electric power, telecommunications, and think tanks across Asia and other regions. Its long-term operational significance stems less from a single canonical campaign than from its role as a widely reused malware codebase within the Chinese threat ecosystem, where actors have adapted it into purpose-built backdoors and cross-platform successors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
First spotted back in 2015, Trochilus is a RAT implemented in C++ and its source code is available for download on GitHub. ... The malware then injects svchost.exe with the ability to: Execute commands Download potentially malicious files.
The URL https://chuanqiliebiao-1314[.]oss-cn-shanghai[.]aliyuncs[.]com/wp-content/plugins/Ssl-update.exe will download a dropper ... dubbed ‘DOUBLESTEP’ ... embedded with TROCHILUS.
Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA
Tooling-wise, APT31 initially used a number of malware families (RAWDOOR, Trochilus, EvilOSX, DropDoor/DropCat, etc.)...
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Baobeilong (宝贝龙/”Baby Dragon”) also maintained a GitHub account that had forked both the Quasar and Trochilus RATs, two open-source tools historically used by STONE PANDA... Falcon Intelligence recently independently conducted detailed analysis of the RedLeaves malware... found it was directly sourced from Trochilus code
To cover the malicious traffic, the attackers registered C2 domains masquerading as normal AWS or AlibabaCloud domains... This cluster of activity has previously targeted entities... using malicious domains that masquerade as services such as Amazon Web Services and Microsoft Support Services.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the open-source RAT lineage from which SprySOCKS code derives.
An open-source Windows remote access tool that served as the basis for SprySOCKS, though SprySOCKS was sufficiently modified to be considered a distinct malware family.
A Windows remote access tool that serves as the codebase foundation for SprySOCKS and RedLeaves.
A Windows remote access trojan that served as the basis for SprySOCKS and has source code overlaps with RedLeaves.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.