TEARDROP
MITRE ATT&CK: S0560 View on attack.mitre.org
Aliases: TEARDROP
- First seen
- 2020-05-01 00:00:00
- Malware type
- dropper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2 (2 malicious)
- Last IoC activity
- 2026-06-26 12:15:22
- Profile updated
- 2026-07-07 12:58:31
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb
Context
TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was likely used by APT29 since at least May 2020.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to TEARDROP (S0560). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | MOTIF_bd842c41b4c1b3c2deb475d7a3876599_refanged.exe | 2026-06-26 | 1 |
| file sample | 93c3fc2cf55dedbf9fe9325f7ed62aa39a289d5f83d6ddffdf282a1278b88c0d.bin | 2026-03-20 | 2 |
Detection coverage
- 2 YARA rules
- 240 Sigma rules
Malware & tools used
- Query Registry (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Modify Registry (attack-pattern)
- Windows Service (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- SolarWinds Compromise (campaign)
- APT29 (threat-actor)
Detection rules
- SIGNATURE_BASE_APT_Dropper_Raw64_TEARDROP_1 (yara-rule)
- SIGNATURE_BASE_APT_Dropper_Win64_TEARDROP_1 (yara-rule)
Reports & references
- CrowdStrike — Report2021Gtr (report)
- medium.com — Identifying Unc2452 Related Techniques 9F7B6C7F3714 (report)
- Mandiant — Evasive Attacker Leverages Solarwinds Supply Chain Compromises With Sunburst Backdoor (report)
- Microsoft — Analyzing Solorigate The Compromised Dll File That Started A Sophisticated Cyberattack And How Microsoft Defender Helps Protect (report)
- github.com — Sunburst Countermeasures (report)
- Microsoft — Goldmax Goldfinder Sibot Analyzing Nobelium Malware (report)
- Palo Alto Unit 42 — Solarphoenix (report)
- Palo Alto Unit 42 — Solarstorm Supply Chain Attack Timeline (report)
- 0xc0decafe.com — Malware Analyst Guide To Pe Timestamps (report)
- brighttalk.com — 462719 (report)
- Mandiant — Unc2452 Merged Into Apt29 (report)
- youtube.com — Watch (report)
- Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
- orangematter.solarwinds.com — New Findings From Our Investigation Of Sunburst (report)
- youtube.com — Watch (report)
- sans.org — Contrarian View Solarwinds 119515 (report)
- file2.api.drift.com — Supply%20Chain%20Attacks %20Cyber%20Criminals%20Target%20The%20Weakest%20Link (report)
- Broadcom/Symantec — Solarwinds Raindrop Malware (report)
- fortinet.com — What We Have Learned So Far About The Sunburst Solarwinds Hack (report)
- blog.securehat.co.uk — Extracting The Cobalt Strike Config From A Teardrop Loader (report)
- blog.bushidotoken.net — Space Invaders Cyber Threats That Are (report)
- Broadcom/Symantec — Attacks Against Government Sector (report)
- Microsoft — Using Microsoft 365 Defender To Coordinate Protection Against Solorigate (report)
- research.checkpoint.com — Sunburst Teardrop And The Netsec New Normal (report)
- Cisco Talos — Solarwinds Supplychain Coverage (report)
External references
- mitre-attack — S0560
- FireEye SUNBURST Backdoor December 2020
- Microsoft Deep Dive Solorigate January 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy