Malware.View on attack.mitre.org
Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was discovered in January 2021 and was likely used since at least May 2020.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm. |
| T1027.003 Steganography |
Raindrop used steganography to locate the start of its encoded payload within legitimate 7-Zip code. |
| T1027.013 Encrypted/Encoded File |
Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key. |
| T1036 Masquerading |
Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code. |
| T1036.005 Match Legitimate Resource Name or Location |
Raindrop was installed under names that resembled legitimate Windows file and directory names. |
| T1140 Deobfuscate/Decode Files or Information |
Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample. |
| T1497.003 Time Based Checks |
After initial installation, Raindrop runs a computation to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.