Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareRaspberry Robin | Raspberry Robin uses mixed-case letters for filenames and commands to evade detection. |
| T1036.008 Masquerade File Type |
MalwareRaspberry Robin | Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder. |
| T1059.003 Windows Command Shell |
MalwareRaspberry Robin | Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071.001 Web Protocols |
MalwareRaspberry Robin | Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution. |
| T1091 Replication Through Removable Media |
MalwareRaspberry Robin | Raspberry Robin has historically used infected USB media to spread to new victims. |
| T1105 Ingress Tool Transfer |
MalwareRaspberry Robin | Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's |
| T1218.007 Msiexec |
MalwareRaspberry Robin | Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution. |
| T1218.008 Odbcconf |
MalwareRaspberry Robin | Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the |
| T1218.010 Regsvr32 |
MalwareRaspberry Robin | Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes. |
| T1218.011 Rundll32 |
MalwareRaspberry Robin | Raspberry Robin uses rundll32 execution without any command line parameters to contact command and control infrastructure, such as IP addresses associated with Tor nodes. |
| T1548.002 Bypass User Account Control |
MalwareRaspberry Robin | Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt. |
| T1571 Non-Standard Port |
MalwareRaspberry Robin | Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic. |
| T1583.001 Domains |
MalwareRaspberry Robin | Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as " |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.