Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareRaspberry Robin | Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime. |
| T1033 System Owner/User Discovery |
MalwareRaspberry Robin | Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges. |
| T1036.004 Masquerade Task or Service |
MalwareRaspberry Robin | Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe. |
| T1047 Windows Management Instrumentation |
MalwareRaspberry Robin | Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package. |
| T1055.012 Process Hollowing |
MalwareRaspberry Robin | Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution. |
| T1057 Process Discovery |
MalwareRaspberry Robin | Raspberry Robin can identify processes running on the victim machine, such as security software, during execution. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1091 Replication Through Removable Media |
MalwareRaspberry Robin | Raspberry Robin has historically used infected USB media to spread to new victims. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaspberry Robin | Raspberry Robin contains several layers of obfuscation to hide malicious code from detection and analysis. |
| T1218.007 Msiexec |
MalwareRaspberry Robin | Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution. |
| T1480 Execution Guardrails |
MalwareRaspberry Robin | Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRaspberry Robin | Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment. |
| T1518.001 Security Software Discovery |
MalwareRaspberry Robin | Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRaspberry Robin | Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: |
| T1548 Abuse Elevation Control Mechanism |
MalwareRaspberry Robin | Raspberry Robin implements a variation of the |
| T1559 Inter-Process Communication |
MalwareRaspberry Robin | Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory. |
| T1559.001 Component Object Model |
MalwareRaspberry Robin | Raspberry Robin creates an elevated COM object for |
| T1574 Hijack Execution Flow |
MalwareRaspberry Robin | Raspberry Robin will drop a copy of itself to a subfolder in |
| T1622 Debugger Evasion |
MalwareRaspberry Robin | Raspberry Robin leverages anti-debugging mechanisms through the use of |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.