TEARDROP — Malware Profile
TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise. It was likely used by APT29 since at least May 2020.
MITRE ATT&CK techniques (6)
- T1012 Query Registry
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1543.003 Windows Service