TEARDROP is a previously unknown memory-only Windows dropper discovered during investigations of the 2020 SolarWinds supply-chain compromise. It was used as a second-stage payload following SUNBURST/SUNSPOT activity and was observed deploying customized Cobalt Strike Beacon, including over HTTP/HTTPS in selected victim environments. Reported behavior includes checking for the registry key HKU\SOFTWARE\Microsoft\CTF before decoding its embedded payload, decoding payload data from gracious_truth.jpg with a rolling XOR algorithm, loading executable code directly into memory without leaving an on-disk payload, and running as a Windows service from C:\Windows\SysWOW64, including creation of registry entries for service persistence. TEARDROP has been associated with the SolarWinds intrusion actor tracked as UNC2452 by FireEye and attributed by Microsoft and other reporting to NOBELIUM/APT29/Cozy Bear/The Dukes, a Russia-linked espionage group. It was identified on some victim machines during follow-on post-exploitation activity after the trojanized SolarWinds Orion update, and reporting states it enabled deployment of Cobalt Strike for domain enumeration, hands-on-keyboard operations, and collection/exfiltration of valuable information. High-confidence file/path details mentioned in the content include C:\Windows\SYSWOW64\netsetupsvc.dll and the payload source gracious_truth.jpg.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
We assess that threat actors will almost certainly continue to develop their capability to compromise organizations through supply chains as an alternative to direct action against a target’s network defences.
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
MITRE ATT&CK Mappings: APT29 Privilege Escalation T1055: Process Injection .002: Portable Executable Injection
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
"SHOTPUT is obscured using XOR encoding and appended to a valid GIF file." / "TEARDROP created and read from a file with a fake JPG header" / "Ramsay has base64-encoded its portable executable and hidden itself under a JPG header."
JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. TEARDROP created and read from a file with a fake JPG header.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
MITRE ATT&CK Mappings: APT29 Privilege Escalation T1055: Process Injection .002: Portable Executable Injection
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage malware delivered in the SUNBURST campaign for selected victims, alongside Cobalt Strike Beacon over HTTP/HTTPS C2.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Memory-only dropper delivered by SUNBURST and used to deploy Cobalt Strike Beacon and potentially other backdoors.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.