ATT&CKReferencesMicrosoft RaspberryRobin 2022

Microsoft RaspberryRobin 2022

Microsoft Threat Intelligence. (2022, October 27). Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity. Retrieved May 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1070.009
Clear Persistence
MalwareRaspberry Robin

Raspberry Robin uses a RunOnce Registry key for persistence, where the key is removed after its use on reboot then re-added by the malware after it resumes execution.

T1204
User Execution
MalwareRaspberry Robin

Raspberry Robin execution can rely on users directly interacting with malicious LNK files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.