TEARDROP

MITRE ATT&CK: S0560 View on attack.mitre.org

Aliases: TEARDROP

First seen
2020-05-01 00:00:00
Malware type
dropper
Family
Malware family
Operating systems
windows
Related IoCs
2 (2 malicious)
Last IoC activity
2026-06-26 12:15:22
Profile updated
2026-07-07 12:58:31

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:gb

Context

TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was likely used by APT29 since at least May 2020.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to TEARDROP (S0560). The 2 most recently updated:

TypeIndicatorUpdatedSources
file sample MOTIF_bd842c41b4c1b3c2deb475d7a3876599_refanged.exe 2026-06-26 1
file sample 93c3fc2cf55dedbf9fe9325f7ed62aa39a289d5f83d6ddffdf282a1278b88c0d.bin 2026-03-20 2

Detection coverage

  • 2 YARA rules
  • 240 Sigma rules

Malware & tools used

  • Query Registry (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Modify Registry (attack-pattern)
  • Windows Service (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

  • SolarWinds Compromise (campaign)
  • APT29 (threat-actor)

Detection rules

  • SIGNATURE_BASE_APT_Dropper_Raw64_TEARDROP_1 (yara-rule)
  • SIGNATURE_BASE_APT_Dropper_Win64_TEARDROP_1 (yara-rule)

Reports & references

  • CrowdStrike — Report2021Gtr (report)
  • medium.com — Identifying Unc2452 Related Techniques 9F7B6C7F3714 (report)
  • Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
  • Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
  • github.com — Sunburst Countermeasures (report)
  • Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
  • Palo Alto Unit 42 — Solarphoenix (report)
  • Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
  • 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
  • brighttalk.com — 462719 (report)
  • Mandiant — Unc2452 Merged Into Apt29 (report)
  • youtube.com — Watch (report)
  • Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
  • orangematter.solarwinds.com — New Findings From Our Investigation Of Sunburst (report)
  • youtube.com — Watch (report)
  • sans.org — Contrarian View Solarwinds 119515 (report)
  • file2.api.drift.com — Supply%20Chain%20Attacks %20Cyber%20Criminals%20Target%20The%20Weakest%20Link (report)
  • Broadcom/Symantec — Solarwinds Raindrop Malware (report)
  • fortinet.com — What We Have Learned So Far About The Sunburst Solarwinds Hack (report)
  • blog.securehat.co.uk — Extracting The Cobalt Strike Config From A Teardrop Loader (report)
  • blog.bushidotoken.net — Space Invaders Cyber Threats That Are (report)
  • Broadcom/Symantec — Attacks Against Government Sector (report)
  • Microsoft — Using Microsoft 365 Defender To Coordinate Protection Against Solorigate (report)
  • research.checkpoint.com — Sunburst Teardrop And The Netsec New Normal (report)
  • Cisco Talos — Solarwinds Supplychain Coverage (report)

External references