Netskope Threat Labs

Raspberry Robin

ATP Sandbox Adv. HeuristicsAV

Raspberry Robin is a worm that spreads through USB drives and is widely used to deliver other malware families such as IcedID and Clop. It infects Windows systems when users plug in contaminated media, and its staged loaders connect to command and control infrastructure that has persisted across many campaigns. Its spread in 7z, LNK, MSI, and other formats shows an operation that continually adapts its delivery formats to slip past defenses.

First seen
December 2022
Last seen
October 2026
RaspberryRobinRaspberryrobin

41 techniques across 9 tactics.

TA0042 Resource Development

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1518Software Discovery

TA0008 Lateral Movement

  • T1091Replication Through Removable Media

TA0011 Command and Control

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Document-HTML.Trojan.RaspberryRobin
Script-BAT.Trojan.RaspberryRobin
Shortcut.Trojan.Raspberryrobin
Trojan.RaspberryRobin.1.Gen
Trojan.RaspberryRobin.2.Gen
Win32.Backdoor.Raspberryrobin
Win32.Backdoor.RaspberryRobin
Win32.Trojan.Raspberryrobin
Win32.Trojan.RaspberryRobin