RainyDay is a Windows remote access trojan and backdoor used by Naikon in cyber-espionage operations targeting military organizations in Southeast Asia. It was incorporated into Naikon’s toolkit from September 2020 during an operation spanning June 2019 to March 2021. It provides remote control of compromised hosts and supports deployment of additional payloads and tools, including the Nebulae backdoor.
RainyDay supports file manipulation and bidirectional transfer, command-shell execution, process enumeration and termination, service manipulation, and screenshot capture. It communicates with command-and-control infrastructure over TCP and HTTP, switching protocols when a channel fails, and supports RC4-encrypted communications. Its execution chain uses legitimate applications to side-load a malicious DLL, which decrypts an XOR-obfuscated payload and executes the backdoor in memory. Deployment has involved self-extracting archives or manual placement of the loading components; these mechanisms do not establish the original initial-access vector.
RainyDay establishes persistence through Windows services and scheduled tasks. Its defensive measures include process protection, concealment of service activity, and masquerading as legitimate software. It can uninstall itself by deleting its service and associated files. Operators have used RainyDay to execute tools that extract local passwords, cached domain credentials, and browser-stored credentials, deploy scanners and reverse proxies, and facilitate lateral movement. Associated file-collection tools monitor local and remote drives for changed documents, stage selected files, and upload them to Dropbox.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RainyDayは、ファイル操作、シェルコマンドの実行、プロセス操作、スクリーンキャプチャなどの機能を備えたRATであり、C2通信にTCPおよびHTTPプロトコルを使用します。
The new variant's features overlap with both the RainyDay and Turian backdoors...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT used by Naikon that supports file operations, shell-command execution, process manipulation and screen capture, with TCP and HTTP C2. It is compared with MetaRAT because their loading shellcode shares an RC4 key and LZNT1 decompression, and some strings and timestomping code are similar. These similarities suggest possible shared development or source code, not confirmed RainyDay deployment or Naikon involvement in this campaign.
Backdoor whose configuration structure is reused by the described PlugX variant; delivered via DLL side-loading and executed in-memory in the described attack chain.
Supports TCP command-and-control communications.
Enterprise New Software: ... RainyDay
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.