TEARDROP

S0560

Malware.View on attack.mitre.org

About this malware

TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was likely used by APT29 since at least May 2020.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1012
Query Registry

TEARDROP checked that HKU\SOFTWARE\Microsoft\CTF existed before decoding its embedded payload.

T1027
Obfuscated Files or Information

TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher.

T1036.005
Match Legitimate Resource Name or Location

TEARDROP files had names that resembled legitimate Window file and directory names.

T1112
Modify Registry

TEARDROP modified the Registry to create a Windows service for itself on a compromised host.

T1140
Deobfuscate/Decode Files or Information

TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload.

T1543.003
Windows Service

TEARDROP ran as a Windows service from the c:\windows\syswow64 folder.

Groups that use it1

Campaigns1

References2

  1. FireEye SUNBURST Backdoor December 2020 Open source
    FireEye. (2020, December 13). Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor. Retrieved January 4, 2021.
  2. Microsoft Deep Dive Solorigate January 2021 Open source
    MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.