RainyDay

S0629

Malware.View on attack.mitre.org

About this malware

RainyDay is a backdoor tool that has been used by Naikon since at least 2020.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

RainyDay can use a file exfiltration tool to collect recently changed files on a compromised host.

T1007
System Service Discovery

RainyDay can create and register a service for execution.

T1008
Fallback Channels

RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working.

T1027.013
Encrypted/Encoded File

RainyDay has downloaded as a XOR-encrypted payload.

T1036.004
Masquerade Task or Service

RainyDay has named services and scheduled tasks to appear benign including "ChromeCheck" and "googleupdate."

T1036.005
Match Legitimate Resource Name or Location

RainyDay has used names to mimic legitimate software including "vmtoolsd.exe" to spoof Vmtools.

T1053.005
Scheduled Task

RainyDay can use scheduled tasks to achieve persistence.

T1057
Process Discovery

RainyDay can enumerate processes on a target system.

T1059.003
Windows Command Shell

RainyDay can use the Windows Command Shell for execution.

T1070.004
File Deletion

RainyDay has the ability to uninstall itself by deleting its service and files.

T1071.001
Web Protocols

RainyDay can use HTTP in C2 communications.

T1074.001
Local Data Staging

RainyDay can use a file exfiltration tool to copy files to C:\ProgramData\Adobe\temp prior to exfiltration.

T1083
File and Directory Discovery

RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions.

T1090
Proxy

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

T1095
Non-Application Layer Protocol

RainyDay can use TCP in C2 communications.

View all 25 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Bitdefender Naikon April 2021 Open source
    Vrabie, V. (2021, April 23). NAIKON – Traces from a Military Cyber-Espionage Operation. Retrieved June 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.