Raindrop is a Windows-based second-stage malware loader associated with the SolarWinds intrusion set and the Russian state-linked espionage actor tracked as APT29, UNC2452, Dark Halo, NOBELIUM, and Cozy Bear. It was identified during investigations into follow-on activity after the SUNBURST backdoor and is closely related to TEARDROP, serving as a variant used to deliver customized Cobalt Strike Beacon payloads onto selected victim systems.
Raindrop is designed primarily as a stealthy in-memory delivery mechanism rather than a full-featured standalone implant. It decrypts and unpacks an embedded Cobalt Strike payload using layered obfuscation and packing, including AES-256 in CBC mode with a unique key per sample, LZMA compression, and additional XOR-based processing. Microsoft characterized Raindrop as a custom loader variant that de-obfuscates payload material from code sections, while other reporting described its use of legitimate-looking names and locations to blend into Windows environments. The malware’s version information and installation artifacts were crafted to masquerade as benign software components, supporting defense evasion during post-compromise operations.
Operationally, Raindrop appeared in a limited subset of high-value SolarWinds victims after hands-on-keyboard activation of earlier access. It was not broadly deployed to all systems that received SUNBURST; instead, it was used selectively as part of tailored follow-on exploitation. Once executed, it installed or launched a customized Cobalt Strike Beacon that enabled further domain enumeration, interactive operator control, collection, and exfiltration activity. Reporting on the broader campaign also links these second-stage deployments to credential theft, privilege escalation, lateral movement, cloud abuse, and long-term espionage objectives, although those downstream actions were generally performed through the delivered Beacon and operator tradecraft rather than by Raindrop alone.
Raindrop is best understood as a bespoke post-compromise loader in a multi-stage espionage workflow. Its role was to bridge initial covert access and more flexible operator-controlled tooling while maintaining stealth through encryption, packing, masquerading, and selective deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop.
Nobelium would then use SUNBURST to deploy additional malware, such as TEARDROP, RAINDROP, and several others.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations, which primarily focuses on an advanced persistent threat (APT) actor’s compromise of SolarWinds Orion products...
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Currently, the tool looks for: ... System, network, and M365 enumeration...
Currently, the tool looks for: ... System, network, and M365 enumeration...
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Mentioned only in relation to an added indicator/domain; the content does not otherwise describe its functionality.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
A loader used to deploy Cobalt Strike payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.