Raindrop is a Windows malware loader designed to deliver customized Cobalt Strike Beacon payloads. It was identified during investigations into the SolarWinds Orion supply-chain compromise and is associated with APT29, also tracked as NOBELIUM, a cyberespionage actor attributed to Russia’s Foreign Intelligence Service. Alongside TEARDROP, it formed part of the campaign’s selective follow-on deployment of malware within compromised environments rather than the initial trojanized Orion update.
Raindrop uses a custom packer with LZMA compression and decrypts its Cobalt Strike payload using AES-256 in CBC mode with a unique key per sample. Its implementation incorporates modified 7-Zip source code, including associated export names, and Far Manager source code. Operators installed it using names resembling legitimate Windows files and directories to conceal its presence. The resulting Cobalt Strike implants supported hands-on-keyboard operations, including domain enumeration, information collection, and exfiltration; those functions belong to the deployed payload rather than the loader itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nobelium would then use SUNBURST to deploy additional malware, such as TEARDROP, RAINDROP, and several others.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations, which primarily focuses on an advanced persistent threat (APT) actor’s compromise of SolarWinds Orion products...
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Currently, the tool looks for: ... System, network, and M365 enumeration...
Currently, the tool looks for: ... System, network, and M365 enumeration...
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Mentioned only in relation to an added indicator/domain; the content does not otherwise describe its functionality.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
A loader used to deploy Cobalt Strike payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.