Raindrop is a Windows malware loader associated with the SolarWinds intrusion set and follow-on operations attributed to APT29, also tracked as NOBELIUM and widely linked to Russia’s SVR. It was identified as a second-stage component used after initial compromise to install a customized Cobalt Strike Beacon on selected victim systems. In SolarWinds-related intrusions, Raindrop functioned as part of the transition from earlier access such as SUNBURST to hands-on-keyboard post-compromise activity, enabling domain enumeration and subsequent collection and exfiltration of valuable information through operator-driven actions.
Raindrop is notable for its payload protection and evasion design. It decrypted its embedded Cobalt Strike payload with AES-256 in CBC mode using a unique key per sample, and the payload was additionally compressed with LZMA and obfuscated with single-byte XOR. Microsoft characterized it as a custom Cobalt Strike loader variant that de-obfuscated content from the code section, and reporting also noted use of a custom packer. The malware was installed under names and version information made to resemble legitimate Windows files and software components, reflecting a deliberate masquerading strategy to reduce suspicion.
Raindrop has been documented on compromised Windows hosts during investigations into the SolarWinds campaign and is commonly discussed alongside TEARDROP as a related second-stage loader family. High-confidence reporting ties it to deployment of Cobalt Strike rather than to a broad standalone feature set of its own. Its primary role is staging and execution of follow-on tooling in targeted enterprise environments during espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop.
Nobelium would then use SUNBURST to deploy additional malware, such as TEARDROP, RAINDROP, and several others.
If further actions were taken, TEARDROP or RAINDROP backdoors would be deployed, which would install a customized Cobalt Strike beacon in the environment, enumerating the domain and allowing for the collection and exfiltration of information of value using hands-on-keyboard techniques.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations, which primarily focuses on an advanced persistent threat (APT) actor’s compromise of SolarWinds Orion products...
State-sponsored threat actors have demonstrated their ability to compromise service providers such as MSPs as a method of infiltrating the supply chain of organizations of strategic interest, establishing persistence, and securing access to downstream targets.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Currently, the tool looks for: ... System, network, and M365 enumeration...
Currently, the tool looks for: ... System, network, and M365 enumeration...
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in supporting material as part of the Solorigate second-stage malware chain from SUNBURST to TEARDROP and RAINDROP.
Mentioned only in relation to an added indicator/domain; the content does not otherwise describe its functionality.
Malware referenced as part of the Solorigate intrusion chain; the content only mentions it through a cited reference and does not describe its behavior further.
A loader used to deploy Cobalt Strike payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.