Netskope Threat Labs

TEARDROP

ATP Sandbox Adv. HeuristicsAV

TEARDROP is a dropper associated with the APT29 group that delivers additional malware payloads through obfuscated code and registry manipulation. Its memory resident design avoided disk artifacts, and researchers discovered it as part of the SolarWinds related intrusion toolkit, where it staged payloads for the espionage operation. Detections under this name indicate nation grade tooling and warrant immediate escalation.

First seen
February 2022
Last seen
October 2026
TearDropTeardrop

6 techniques across 4 tactics.

TA0003 Persistence

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1036Masquerading
    • T1036.005Match Legitimate Resource Name or Location
  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

TA0112 Defense Impairment

Alert Name
Binary.Dropper.Teardrop
Generic.Teardrop.1.0AE948D6
Generic.Teardrop.1.0EA491C3
Generic.Teardrop.1.16969AAC
Generic.Teardrop.1.1BBA9B81
Generic.Teardrop.1.1D998FE1
Generic.Teardrop.1.229FA5C3
Generic.Teardrop.1.244AC43A
Generic.Teardrop.1.2CBF50EA
Generic.Teardrop.1.2D07DDA7