RainyDay, also known as FoundCore, is a Windows backdoor associated with the China-linked Naikon espionage group. It has been used as a first-stage implant in intrusions targeting military and government-related organizations in Southeast Asia, where it served as an access platform for reconnaissance, persistence, tool deployment, and delivery of additional payloads including the Nebulae backdoor.
RainyDay supports remote command-and-control over both TCP and HTTP and can switch between those protocols when one channel is unavailable, improving communication resilience. Its communications have been observed protected with RC4, and payload components may be decrypted with XOR-based routines. The malware can enumerate processes, access a command shell, capture screenshots, manipulate files, and support collection and exfiltration of data. Reported follow-on tooling used alongside RainyDay included utilities for harvesting credentials from web browsers and collecting recently changed files for exfiltration, including staging data locally and uploading selected files to cloud storage.
For persistence and execution, RainyDay has used Windows scheduled tasks and services, and it has also been launched through DLL side-loading techniques. It has employed masquerading by adopting names resembling legitimate software components. The malware also includes self-removal functionality, allowing operators to uninstall it by deleting its service and associated files.
Operationally, RainyDay has been linked to broader Naikon tradecraft that included reconnaissance, password dumping, lateral movement, and deployment of secondary tools in long-running cyber-espionage campaigns. Its role is best characterized as a modular backdoor used to establish and maintain footholds on compromised Windows systems while enabling follow-on collection and post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In the same series of attacks, the Naikon threat actors also delivered first-stage malware known as RainyDay or FoundCore used to deploy second-stage payloads and tools used for various purposes, including the Nebulae backdoor.
The new variant's features overlap with both the RainyDay and Turian backdoors...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Besides deploying additional payloads on compromised systems, attackers can also send RainyDay commands over TCP or HTTP to ... access a command shell...
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Using the RainyDay backdoor, the actors performed reconnaissance, uploaded its reverse proxy tools and scanners, executed the password dump tools...
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
attackers can also send RainyDay commands over TCP or HTTP...
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
Using the RainyDay backdoor, the actors performed reconnaissance, uploaded its reverse proxy tools and scanners...
RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working. Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2. NETEAGLE will send beacons via UDP/6000 if no proxy is configured.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor whose configuration structure is reused by the described PlugX variant; delivered via DLL side-loading and executed in-memory in the described attack chain.
Enterprise New Software: ... RainyDay
Backdoor that can encrypt C2 communications with RC4.
Malware/tool that uses native APIs such as ReadDirectoryChangeW for folder monitoring and file collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.