SYMBOLCOMMON_NAMEaka. SYNONYMS
win.beatdrop (Back to overview)

BEATDROP

Actor(s): APT29

VTCollection    

According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.

References
2023-07-26 ⋅ ⋅ Weixin ⋅ Anheng Threat Intelligence Center
APT29 recently faked the German embassy and issued a malicious PDF file
BEATDROP Unidentified 107 (APT29)
2023-03-10 ⋅ Mrtiepolo ⋅ Gianluca Tiepolo
Sophisticated APT29 Campaign Abuses Notion API to Target the European Commission
BEATDROP EnvyScout GraphicalNeutrino tDiscoverer VaporRage
2022-09-06 ⋅ ⋅ INCIBE-CERT ⋅ INCIBE
Estudio del análisis de Nobelium
BEATDROP BOOMBOX Cobalt Strike EnvyScout Unidentified 099 (APT29 Dropbox Loader) VaporRage
2022-07-19 ⋅ R136a1 ⋅ Dominik Reichel
A look into APT29's new early-stage Google Drive downloader
BEATDROP BOOMBOX Gdrive Unidentified 098 (APT29 Slack Downloader)
2022-04-29 ⋅ Mandiant ⋅ Anders Vejlby, John Wolfram, Nick Simonian, Sarah Hawley, Tyler McLellan
Trello From the Other Side: Tracking APT29 Phishing Campaigns
BEATDROP VaporRage
Yara Rules
[TLP:WHITE] win_beatdrop_auto (20260917 | Detects win.beatdrop.)
rule win_beatdrop_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.beatdrop."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.beatdrop"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4133948c00080000 89c1 0fb6ef 440fb6c2 c1e918 418b0c8c 43338c84000c0000 }
            // n = 7, score = 400
            //   4133948c00080000     | mov                 eax, dword ptr [ebx + 8]
            //   89c1                 | dec                 eax
            //   0fb6ef               | sub                 eax, 8
            //   440fb6c2             | dec                 eax
            //   c1e918               | add                 esp, 0x28
            //   418b0c8c             | pop                 ebx
            //   43338c84000c0000     | dec                 eax

        $sequence_1 = { 45339c8d00080000 4489c1 41c1e918 478b4c8d00 45338c9d000c0000 }
            // n = 5, score = 400
            //   45339c8d00080000     | shr                 edx, 0x18
            //   4489c1               | movzx               ebx, bl
            //   41c1e918             | shr                 ebx, 0x10
            //   478b4c8d00           | shr                 edx, 0x18
            //   45338c9d000c0000     | movzx               ebx, bl

        $sequence_2 = { 4733bc8500040000 4533bc9d00080000 0fb6ce 4589f2 4589f9 4189c0 894c2404 }
            // n = 7, score = 400
            //   4733bc8500040000     | dec                 eax
            //   4533bc9d00080000     | mov                 eax, dword ptr [ebx + 8]
            //   0fb6ce               | dec                 eax
            //   4589f2               | add                 eax, 0x40
            //   4589f9               | dec                 eax
            //   4189c0               | mov                 eax, dword ptr [eax + 8]
            //   894c2404             | dec                 eax

        $sequence_3 = { 0fb6db 4189f3 418b448500 33555c 41c1eb18 }
            // n = 5, score = 400
            //   0fb6db               | lea                 ecx, [0xd9e0]
            //   4189f3               | inc                 esp
            //   418b448500           | mov                 dword ptr [esp + 0x20], eax
            //   33555c               | dec                 esp
            //   41c1eb18             | lea                 ebp, [esp + 0x70]

        $sequence_4 = { 488384248800000010 0f1100 483b7c2420 7434 488b442428 4809f8 a807 }
            // n = 7, score = 400
            //   488384248800000010     | dec    esp
            //   0f1100               | mov                 ecx, ebp
            //   483b7c2420           | dec                 eax
            //   7434                 | lea                 edx, [0x11518]
            //   488b442428           | dec                 eax
            //   4809f8               | lea                 ecx, [0x11c30]
            //   a807                 | jmp                 0x184f

        $sequence_5 = { c1ee18 c1ea10 338590000000 458b74b500 4489c1 0fb6d2 }
            // n = 6, score = 400
            //   c1ee18               | dec                 eax
            //   c1ea10               | lea                 ecx, [0x1249f]
            //   338590000000         | dec                 esp
            //   458b74b500           | lea                 ebp, [esp + 0x20]
            //   4489c1               | inc                 ecx
            //   0fb6d2               | mov                 dl, byte ptr [esp]

        $sequence_6 = { 418b1484 4489c0 43339494000c0000 4589c2 c1e810 339690000000 41c1ea18 }
            // n = 7, score = 400
            //   418b1484             | mov                 ecx, esi
            //   4489c0               | dec                 eax
            //   43339494000c0000     | mov                 ecx, esi
            //   4589c2               | dec                 esp
            //   c1e810               | mov                 ecx, esp
            //   339690000000         | dec                 eax
            //   41c1ea18             | mov                 edx, edi

        $sequence_7 = { 448b4c240c 410fcb 44895904 470fb60c0c 41c1e118 4531c8 }
            // n = 6, score = 400
            //   448b4c240c           | mov                 eax, eax
            //   410fcb               | dec                 eax
            //   44895904             | lea                 eax, [ecx + 0x10]
            //   470fb60c0c           | dec                 eax
            //   41c1e118             | mov                 ebx, ecx
            //   4531c8               | dec                 ecx

        $sequence_8 = { 45338c9d000c0000 4489c3 450fb6c0 c1eb10 }
            // n = 4, score = 400
            //   45338c9d000c0000     | inc                 ecx
            //   4489c3               | mov                 eax, 0x184e
            //   450fb6c0             | dec                 eax
            //   c1eb10               | lea                 edx, [0x1247c]

        $sequence_9 = { 4489c8 450fb6c9 c1e818 418b0484 43338494000c0000 4189da c1eb18 }
            // n = 7, score = 400
            //   4489c8               | dec                 eax
            //   450fb6c9             | lea                 eax, [0x13467]
            //   c1e818               | jmp                 0x1d50
            //   418b0484             | dec                 eax
            //   43338494000c0000     | lea                 eax, [0x13462]
            //   4189da               | jmp                 0x1d50
            //   c1eb18               | dec                 eax

    condition:
        7 of them and filesize < 584704
}
Download all Yara Rules