TEARDROP is a Windows memory-resident second-stage malware used in the SolarWinds supply-chain intrusion commonly tracked as SolarStorm or Solorigate and attributed by Microsoft to NOBELIUM. It was delivered after compromise by the SUNBURST backdoor embedded in trojanized SolarWinds Orion software and functioned as a loader or dropper for a customized Cobalt Strike Beacon used in post-compromise operations.
TEARDROP was designed for stealth. It was described as memory-only in observed deployments and used a custom rolling XOR decoding routine to unpack and execute its payload in memory. In at least some reporting, it also masqueraded through filenames resembling legitimate Windows files and established persistence by modifying the Windows Registry to create a service on compromised hosts. Its primary observed role was to stage and launch customized Cobalt Strike tooling after the attackers had already selected a victim for deeper exploitation.
TEARDROP is closely associated with the broader SolarWinds intrusion lifecycle, in which SUNBURST provided initial covert access, reconnaissance, and selective victim triage before delivering follow-on payloads. The overall campaign targeted high-value government and private-sector organizations and was notable for extensive defense evasion, selective activation, credential theft, privilege escalation, lateral movement, and data theft in later phases. TEARDROP itself is best characterized as a stealthy in-memory payload launcher used during post-compromise operations on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop.
Nobelium would then use SUNBURST to deploy additional malware, such as TEARDROP, RAINDROP, and several others.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
In the SolarWinds incident, attackers embedded their malicious payload on a legitimate component of the SolarWinds Orion Platform software... FireEye named the backdoored version of the DLL file as SUNBURST. The SUNBURST backdoor delivers different payloads, such as... TEARDROP... deploys... Cobalt Strike Beacon.
SunBurst, the malware installed on SolarWinds’ Orion product, perpetrated what seems like a nation-state sponsored supply chain attack
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Use the backdoor access on compromised devices to steal credentials, escalate privileges, and move laterally across on-premises environments to gain the ability to create SAML tokens
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The TEARDROP malware used in the breach reads from the file gracious_truth.jpg that includes a malicious payload.
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
SETTING_SPAWNTO_X86: %windir%\syswow64\msinfo32.exe SETTING_SPAWNTO_X64: %windir%\sysnative\control.exe
Currently, the tool looks for: The presence of malware identified by security researchers as TEARDROP and RAINDROP; Credential dumping certificate pulls; Certain persistence mechanisms identified as associated with this campaign...
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Currently, the tool looks for: ... System, network, and M365 enumeration...
Currently, the tool looks for: ... System, network, and M365 enumeration...
Access cloud resources to search for accounts of interest and exfiltrate emails
TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage malware delivered in the SUNBURST campaign for selected victims, alongside Cobalt Strike Beacon over HTTP/HTTPS C2.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Memory-only dropper delivered by SUNBURST and used to deploy Cobalt Strike Beacon and potentially other backdoors.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.