TEARDROP is a Windows memory-only second-stage malware loader used in the SolarWinds intrusion campaign commonly tracked as SUNBURST or Solorigate and attributed by multiple vendors to the actor Microsoft calls NOBELIUM, also tracked as UNC2452 or Dark Halo. It was selectively deployed after initial compromise rather than broadly delivered to all infected SolarWinds Orion victims. TEARDROP operated as a Windows service, modified the Registry to establish that service, spawned a thread, read an encoded payload from a file disguised as an image, decoded it with a custom rolling XOR algorithm, and manually loaded the resulting payload into memory. Its primary observed role was to execute a customized Cobalt Strike Beacon for follow-on post-compromise operations.
The malware was used after the SUNBURST backdoor had already established access in victim environments. In at least one documented intrusion chain, SUNBURST delivered TEARDROP as a follow-on payload. Reporting also describes TEARDROP as installed via a loader during later-stage operations. The malware used naming intended to resemble legitimate Windows files and directories, consistent with broader defense-evasion tradecraft seen throughout the campaign.
TEARDROP is best characterized as a stealthy in-memory loader supporting post-exploitation. Its observed behavior emphasizes defense evasion and payload staging rather than broad standalone functionality. It was associated with high-value victim intrusions in a campaign that targeted government and private-sector organizations worldwide, including sectors such as government, technology, telecommunications, healthcare, manufacturing, finance, retail, universities, and semiconductor organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop.
Nobelium would then use SUNBURST to deploy additional malware, such as TEARDROP, RAINDROP, and several others.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
SunBurst, the malware installed on SolarWinds’ Orion product, perpetrated what seems like a nation-state sponsored supply chain attack
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
manually load an embedded payload into memory using a custom PE-like file format
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
manually load an embedded payload into memory using a custom PE-like file format
decode an embedded payload using a custom XOR rolling algorithm
SETTING_SPAWNTO_X86: %windir%\syswow64\msinfo32.exe SETTING_SPAWNTO_X64: %windir%\sysnative\control.exe
Currently, the tool looks for: The presence of malware identified by security researchers as TEARDROP and RAINDROP; Credential dumping certificate pulls; Certain persistence mechanisms identified as associated with this campaign...
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Currently, the tool looks for: ... System, network, and M365 enumeration...
Currently, the tool looks for: ... System, network, and M365 enumeration...
Access cloud resources to search for accounts of interest and exfiltrate emails
TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
66 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage malware delivered in the SUNBURST campaign for selected victims, alongside Cobalt Strike Beacon over HTTP/HTTPS C2.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Memory-only dropper delivered by SUNBURST and used to deploy Cobalt Strike Beacon and potentially other backdoors.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.