BEATDROP
- Malware type
- downloader
- Profile updated
- 2026-07-07 14:48:38
Context
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_M_APT_Downloader_BEATDROP (yara-rule)
- MALPEDIA_Win_Beatdrop_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Beatdrop (report)
- mrtiepolo.medium.com — Sophisticated Apt29 Campaign Abuses Notion Api To Target The European Commission 200188059F58 (report)
- Mandiant — Tracking Apt29 Phishing Campaigns (report)
- r136a1.info — A Look Into Apt29S New Early Stage Google Drive Downloader (report)
- incibe-cert.es — Incibe Cert Estudio Analisis Nobelium 2022 V1 (report)
- mp.weixin.qq.com — S (report)
- incibe.es — Incibe Cert Estudio Analisis Nobelium 2022 V1 (report)