Raindrop

MITRE ATT&CK: S0565 View on attack.mitre.org

Aliases: Raindrop

First seen
2020-05-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:42:09

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was discovered in January 2021 and was likely used since at least May 2020.

Detection coverage

  • 72 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • Software Packing (attack-pattern)
  • Masquerading (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Steganography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Time Based Checks (attack-pattern)

Used by threat actors

  • SolarWinds Compromise (campaign)
  • APT29 (threat-actor)

Reports & references

  • ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
  • Mandiant — Unc2452 Merged Into Apt29 (report)
  • Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
  • youtube.com — Watch (report)
  • sans.org — Contrarian View Solarwinds 119515 (report)
  • file2.api.drift.com — Supply%20Chain%20Attacks %20Cyber%20Criminals%20Target%20The%20Weakest%20Link (report)
  • Broadcom/Symantec — Solarwinds Raindrop Malware (report)
  • blog.bushidotoken.net — Space Invaders Cyber Threats That Are (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Raindrop (report)
  • Broadcom/Symantec — Attacks Against Government Sector (report)
  • MITRE ATT&CK — S0565 (report)

External references