Raindrop — Malware Profile
Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was discovered in January 2021 and was likely used since at least May 2020.
MITRE ATT&CK techniques (7)
- T1027.002 Software Packing
- T1027.003 Steganography
- T1027.013 Encrypted/Encoded File
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1497.003 Time Based Checks