Symantec Threat Hunter Team. (2021, January 18). Raindrop: New Malware Discovered in SolarWinds Investigation. Retrieved January 19, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.006 Windows Remote Management |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts. |
| T1027.002 Software Packing |
MalwareRaindrop | Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm. |
| T1027.003 Steganography |
MalwareRaindrop | Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code. |
| T1027.013 Encrypted/Encoded File |
MalwareRaindrop | Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key. |
| T1036 Masquerading |
MalwareRaindrop | Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRaindrop | Raindrop was installed under names that resembled legitimate Windows file and directory names. |
| T1090.001 Internal Proxy |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaindrop | Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware. |
| T1497.003 Time Based Checks |
MalwareRaindrop | After initial installation, Raindrop runs a computation to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.