ATT&CKReferencesSymantec RAINDROP January 2021

Symantec RAINDROP January 2021

Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1021.006
Windows Remote Management
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts.

T1027.002
Software Packing
MalwareRaindrop

Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm.

T1027.003
Steganography
MalwareRaindrop

Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code.

T1027.013
Encrypted/Encoded File
MalwareRaindrop

Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key.

T1036
Masquerading
MalwareRaindrop

Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code.

T1036.005
Match Legitimate Resource Name or Location
MalwareRaindrop

Raindrop was installed under names that resembled legitimate Windows file and directory names.

T1090.001
Internal Proxy
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

T1140
Deobfuscate/Decode Files or Information
MalwareRaindrop

Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample.

T1140
Deobfuscate/Decode Files or Information
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware.

T1497.003
Time Based Checks
MalwareRaindrop

After initial installation, Raindrop runs a computation to delay execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.