{"schema":"aeternae-malware-metadata/v1","generated_at":"2026-10-08T08:40:31+00:00","total_matching":1,"page":1,"page_size":200,"records":[{"id":"844410fcba875c529f987aa880f12bdeada3af3b982a9951ad2cb4f94b74e9b3","kind":"reference","title":"RainyDay - S0629","family":"RainyDay - S0629","category":"Malware intelligence","summary":"Name of ATT&CK software | [RainyDay](https://attack.mitre.org/software/S0629) is a backdoor tool that has been used by [Naikon](https://attack.mitre.org/groups/G0019) since at least 2020.(Citation: Bitdefender Naikon April 2021)","first_seen":1759089007,"last_seen":1759089007,"created_at":1791440271,"updated_at":1791440271,"source_count":1,"data":{"context":"2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"RainyDay - S0629\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json"],"filenames":[],"features":[],"related_cves":[],"labels":["RainyDay - S0629"]},"observations":[{"source_id":"talos_ioc","source_url":"https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","source_label":"RainyDay - S0629","evidence_class":"provider_reported","confidence":null,"observed_at":1759089007,"fetched_at":1791440271,"data":{"context":"2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json","tags":["misp:galaxy-name=\"Malware\"","misp:galaxy-type=\"mitre-malware\"","misp-galaxy:mitre-malware=\"RainyDay - S0629\""],"aliases":[],"references":["https://github.com/Cisco-Talos/IOCs/blob/main/2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json"],"family":"RainyDay - S0629"}}],"indicators":[]}]}