Raspberry Robin
Malware⚠️ Overview
Raspberry Robin is a sophisticated worm first documented in September 2021 by Red Canary, attributed to a financially motivated threat cluster tracked as UNC-2150 by Mandiant, and categorized as a modular loader and propagation worm often used as an initial access broker for ransomware deployments.
🔧 Technical Capabilities
Raspberry Robin propagates primarily through removable USB drives using a LNK shortcut file that executes cmd.exe to launch a malicious DLL via rundll32.exe. It utilizes Tor network nodes for command-and-control communication, frequently connecting to .onion addresses and employing MSI installer payloads fetched from Discord CDN, GitHub repositories, and compromised WordPress sites. Persistence is achieved through scheduled tasks and registry Run keys, while evasion techniques include heavy use of obfuscated JavaScript, Windows Script Host, and checking for virtualized environments or sandbox artifacts. The malware downloads additional payloads such as Fork, Glupteba, or Truebot depending on the victim’s profile, as documented by Red Canary (MITRE ATT&CK ID T1091 for replication through removable media, T1071.001 for web protocols).
📜 History & Notable Incidents
First observed in 2021, Raspberry Robin saw a major campaign surge in mid-2022 targeting technology and manufacturing sectors, with Microsoft reporting in July 2022 that the worm acted as a loader for Clop and LockBit ransomware operators. In October 2022, the same infrastructure was linked to a campaign exploiting the Follina vulnerability (CVE-2022-30190) to gain initial access, as detailed in a Cisco Talos report. No law enforcement takedowns have specifically targeted Raspberry Robin as of early 2025.
🔍 Detection Indicators
Known IOCs include outbound connections to Tor exit nodes on ports 80/443, file creation of randomly named LNK files on USB drives, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Red Canary has published SHA256 hashes for early variants (e.g., 4e7c8a9b1f2d3e4c5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8). Behavioral signatures include repeated spawning of msiexec.exe or regsvr32.exe from USB drive execution.
☠️ Risk & Impact
Raspberry Robin primarily functions as a delivery mechanism for secondary malware, leading to data exfiltration and ransomware deployment in victim environments. According to Mandiant, the worm has been linked to incidents in the technology, manufacturing, and retail sectors, with financial losses from follow-on ransomware attacks exceeding tens of millions of dollars globally. The worm’s ability to spread via USB also poses physical security risks in air-gapped networks.
🛡️ Mitigation
Defenders should disable AutoPlay on all USB devices, enforce Group Policy restrictions on LNK file execution from removable media, and deploy endpoint detection rules monitoring for rundll32.exe launching DLLs from non-standard paths. Microsoft Defender for Endpoint provides detection logic under alert “Raspberry Robin worm behavior,” and organizations should reference Red Canary’s threat hunting queries and MITRE ATT&CK techniques for proactive monitoring.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.