Raindrop
MITRE ATT&CK: S0565 View on attack.mitre.org
Aliases: Raindrop
- First seen
- 2020-05-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:42:09
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was discovered in January 2021 and was likely used since at least May 2020.
Detection coverage
- 72 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- Software Packing (attack-pattern)
- Masquerading (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Steganography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Time Based Checks (attack-pattern)
Used by threat actors
- SolarWinds Compromise (campaign)
- APT29 (threat-actor)
Reports & references
- ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
- Mandiant — Unc2452 Merged Into Apt29 (report)
- Microsoft — Deep Dive Into The Solorigate Second Stage Activation From Sunburst To Teardrop And Raindrop (report)
- youtube.com — Watch (report)
- sans.org — Contrarian View Solarwinds 119515 (report)
- file2.api.drift.com — Supply%20Chain%20Attacks %20Cyber%20Criminals%20Target%20The%20Weakest%20Link (report)
- Broadcom/Symantec — Solarwinds Raindrop Malware (report)
- blog.bushidotoken.net — Space Invaders Cyber Threats That Are (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Raindrop (report)
- Broadcom/Symantec — Attacks Against Government Sector (report)
- MITRE ATT&CK — S0565 (report)