ATT&CKSoftwareRaspberry Robin

Raspberry Robin

S1130

Malware.View on attack.mitre.org

About this malware

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee. The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak." The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.

Techniques used41

Procedure examples41

TechniqueProcedure example
T1027
Obfuscated Files or Information

Raspberry Robin uses mixed-case letters for filenames and commands to evade detection.

T1027.002
Software Packing

Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime.

T1033
System Owner/User Discovery

Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges.

T1036.004
Masquerade Task or Service

Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe.

T1036.008
Masquerade File Type

Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder.

T1047
Windows Management Instrumentation

Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package.

T1055.012
Process Hollowing

Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution.

T1057
Process Discovery

Raspberry Robin can identify processes running on the victim machine, such as security software, during execution.

T1059
Command and Scripting Interpreter

Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution.

T1059.003
Windows Command Shell

Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation.

T1070.004
File Deletion

Raspberry Robin can delete its initial delivery script from disk during execution.

T1070.009
Clear Persistence

Raspberry Robin uses a RunOnce Registry key for persistence, where the key is removed after its use on reboot then re-added by the malware after it resumes execution.

T1071
Application Layer Protocol

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1071.001
Web Protocols

Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution.

T1082
System Information Discovery

Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature.

View all 41 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Avast RaspberryRobin 2022 Open source
    Jan Vojtěšek. (2022, September 22). Raspberry Robin’s Roshtyak: A Little Lesson in Trickery. Retrieved May 17, 2024.
  2. HP RaspberryRobin 2024 Open source
    Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.
  3. Microsoft RaspberryRobin 2022 Open source
    Microsoft Threat Intelligence. (2022, October 27). Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity. Retrieved May 17, 2024.
  4. RedCanary RaspberryRobin 2022 Open source
    Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.
  5. TrendMicro RaspberryRobin 2022 Open source
    Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.