Malware.View on attack.mitre.org
Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee. The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak." The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Raspberry Robin uses mixed-case letters for filenames and commands to evade detection. |
| T1027.002 Software Packing |
Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime. |
| T1033 System Owner/User Discovery |
Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges. |
| T1036.004 Masquerade Task or Service |
Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe. |
| T1036.008 Masquerade File Type |
Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder. |
| T1047 Windows Management Instrumentation |
Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package. |
| T1055.012 Process Hollowing |
Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution. |
| T1057 Process Discovery |
Raspberry Robin can identify processes running on the victim machine, such as security software, during execution. |
| T1059 Command and Scripting Interpreter |
Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution. |
| T1059.003 Windows Command Shell |
Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation. |
| T1070.004 File Deletion |
Raspberry Robin can delete its initial delivery script from disk during execution. |
| T1070.009 Clear Persistence |
Raspberry Robin uses a |
| T1071 Application Layer Protocol |
Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071.001 Web Protocols |
Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution. |
| T1082 System Information Discovery |
Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.