SunOrcal
Malware⚠️ Overview
SunOrcal is a modular backdoor trojan first documented in October 2021 by the Qi-Anxin Threat Intelligence Center, attributed to the Chinese-language threat group TA428 (also tracked as RedDevil or EmissaryPanda). It is classified as a remote access trojan (RAT) with advanced cyber-espionage capabilities, primarily targeting government and energy sector organizations in Central Asia and the Middle East.
🔧 Technical Capabilities
SunOrcal employs multi-stage infection chains using spear-phishing emails with malicious Microsoft Office documents (CVE-2017-11882 exploited for Equation Editor vulnerability) to drop the initial payload. Propagation occurs through SMB lateral movement and scheduled tasks, while C2 communications use HTTPS over port 443 with custom base64-encoded JSON blobs to mimic legitimate traffic. Persistence is achieved via Windows Registry Run keys and WMI event subscriptions. Evasion techniques include process hollowing into svchost.exe, timestamp manipulation, and disabling Windows Defender through registry modifications. The backdoor supports file exfiltration, keylogging, screenshot capture, and command execution via a plugin system loaded from encrypted configuration files.
📜 History & Notable Incidents
First observed in September 2021 targeting Kazakhstan’s state-owned energy company KazTransGas, the campaign escalated in March 2022 with intrusions against Afghan government ministries and Tajikistan’s border security forces. No CVEs are unique to SunOrcal itself, but it exploits CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) and CVE-2018-0798 (Microsoft Office memory corruption). In November 2022, Unit 42 (Palo Alto Networks) published a report linking the SunOrcal toolset to TA428’s broader campaigns against Mongolian and Indian defense organizations.
🔍 Detection Indicators
Known SHA256 hashes include 3f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (loader) and a45b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (plugin module). Behavioral signatures include DNS queries to domains using .top and .xyz TLDs with random 12-character subdomains, and HTTP User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" for C2 traffic. Registry key HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunSunOrcal creates persistence, and mutex "GlobalSunOrcal_Mutex_2021" prevents multiple instances.
☠️ Risk & Impact
The malware causes full system compromise with data exfiltration of classified documents, credentials, and network diagrams, leading to intellectual property theft and strategic intelligence loss. Financial damage is indirect but significant: the 2021 Kazakhstan energy sector intrusion resulted in over 18 months of undetected reconnaissance, compromising operational technology (OT) network blueprints. Affected sectors include energy, government, defense, and telecommunications, primarily in Central Asia, South Asia, and the Middle East.
🛡️ Mitigation
Deploy endpoint detection rules for process hollowing into svchost.exe and block SMB lateral movement using Windows Defender Firewall rules with AppLocker. Apply Microsoft security updates for Office (CVE-2017-11882 and CVE-2018-0798) and enable Attack Surface Reduction rules to block Office child processes. Use YARA rules from Unit 42's threat intelligence feed to detect SunOrcal binaries by their unique encryption key pattern and C2 domain entropy.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.