BEATDROP is a C-based downloader associated with the Russian SVR-linked espionage group APT29, also tracked as Cozy Bear and Nobelium. It was used in phishing-led intrusion activity against diplomatic organizations in Europe, the Americas, and Asia during 2022. The malware is part of APT29’s broader tradecraft of blending malicious operations with legitimate online services to reduce detection opportunities.
BEATDROP uses Atlassian Trello as its command-and-control channel. It collects victim information, retrieves AES-encrypted shellcode from Trello-hosted content, and executes follow-on payloads in memory. Reported execution behavior includes spawning a suspended process and injecting shellcode, as well as mapping its own copy of ntdll.dll to help evade security monitoring. After retrieving payloads, it deletes them from Trello, further reducing forensic visibility.
The malware functions as an intermediate delivery component rather than a final espionage payload, enabling APT29 to stage additional tooling after initial compromise. Its observed use aligns with APT29’s long-running focus on stealthy cyber-espionage against governments, diplomatic entities, and foreign-policy-related targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On 28 April, Mandiant published a report on tracking APT29 phishing campaigns targeting diplomatic organizations in Europe, the Americas, and Asia. It included the disclosure of two new APT29 malware families uncovered in 2022, dubbed BEATDROP and BOOMMIC.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
exfiltrates it to a remote server using api[.]trello[.]com ... abuse of Atlassian's Trello API service: api[.]trello[.]com ... use of the legitimate Dropbox service api[.]dropbox[.]com as communication vector.
This DLL leverages Notion’s API to perform C2 communications via a Notion database and to deliver additional payloads to the victim’s machine.
Known Malware: APT29 GraphicalNeutrino - A backdoor used to target Windows devices that uses notion databases as a C2... ICEBEAT - A downloader malware that uses the open source Zulip messaging platform for C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C-based downloader that uses Trello for command-and-control and executes shellcode in memory via mapped ntdll.dll and suspended thread creation.
BEATDROP is one of two malware families disclosed by Mandiant as used in APT29 phishing campaigns targeting diplomatic organizations, with efforts to evade detection and abuse Trello API services.
Downloader and in-memory loader that maps its own ntdll.dll, spawns a suspended thread, and injects shellcode to evade detection while loading Cobalt Strike.
Downloader written in C that uses Trello for command and control and maps its own copy of ntdll.dll into memory to execute shellcode in its own process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.