Raindrop

S0565

Malware.View on attack.mitre.org

About this malware

Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was discovered in January 2021 and was likely used since at least May 2020.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.002
Software Packing

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.003
Steganography

Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code.

T1027.013
Encrypted/Encoded File

Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key.

T1036
Masquerading

Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code.

T1036.005
Match Legitimate Resource Name or Location

Raindrop was installed under names that resembled legitimate Windows file and directory names.

T1140
Deobfuscate/Decode Files or Information

Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample.

T1497.003
Time Based Checks

After initial installation, Raindrop runs a computation to delay execution.

Groups that use it1

Campaigns1

References2

  1. Microsoft Deep Dive Solorigate January 2021 Open source
    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
  2. Symantec RAINDROP January 2021 Open source
    Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.