Description
Raspberry Robin is a worm that spreads through USB drives and is widely used to deliver other malware families such as IcedID and Clop. It infects Windows systems when users plug in contaminated media, and its staged loaders connect to command and control infrastructure that has persisted across many campaigns. Its spread in 7z, LNK, MSI, and other formats shows an operation that continually adapts its delivery formats to slip past defenses.
Stats
- First seen
- December 2022
- Last seen
- October 2026
Also known as
RaspberryRobinRaspberryrobin
MITRE ATT&CK techniques
41 techniques across 9 tactics.
TA0002 Execution
TA0004 Privilege Escalation
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.002Software Packing
- T1027Obfuscated Files or Information
- T1027.002Software Packing
- T1036Masquerading
- T1055Process Injection
- T1055.012Process Hollowing
- T1070Indicator Removal
- T1140Deobfuscate/Decode Files or Information
- T1218System Binary Proxy Execution
- T1480Execution Guardrails
- T1497Virtualization/Sandbox Evasion
- T1497.001System Checks
- T1574Hijack Execution Flow
- T1574.001DLL
- T1622Debugger Evasion
TA0007 Discovery
TA0008 Lateral Movement
- T1091Replication Through Removable Media
TA0011 Command and Control
TA0112 Defense Impairment
- T1685Disable or Modify Tools
Alert name variants
| Alert Name |
|---|
| Document-HTML.Trojan.RaspberryRobin |
| Script-BAT.Trojan.RaspberryRobin |
| Shortcut.Trojan.Raspberryrobin |
| Trojan.RaspberryRobin.1.Gen |
| Trojan.RaspberryRobin.2.Gen |
| Win32.Backdoor.Raspberryrobin |
| Win32.Backdoor.RaspberryRobin |
| Win32.Trojan.Raspberryrobin |
| Win32.Trojan.RaspberryRobin |
