Raspberry Robin

MITRE ATT&CK: S1130 View on attack.mitre.org

Aliases: LINK_MSIEXEC, QNAP-Worm, RaspberryRobin, Raspberry Robin

First seen
2021-09-01 00:00:00
Malware type
worm, loader, dropper
Family
Malware family
Operating systems
windows
Related IoCs
322 (279 malicious)
Last IoC activity
2026-09-02 00:35:05
Profile updated
2026-07-07 13:08:30

Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee. The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak." The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.

Recent IoC activity

279 malicious indicators in Maltiverse are attributed to Raspberry Robin (S1130). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname 27o.nl 2026-09-03 2
hostname 8t.pm 2026-09-03 4
hostname zk.qa 2026-09-03 1
hostname 1j4.xyz 2026-09-03 2
hostname 4k1.xyz 2026-09-03 2
hostname eznb.net 2026-09-03 2
hostname vqdn.net 2026-09-03 2
hostname lgf.pw 2026-09-03 2
hostname soft.ac 2026-09-03 1
hostname egso.net 2026-09-03 2
hostname 5kx.me 2026-09-03 2
hostname l5k.xyz 2026-09-03 2
hostname as3.biz 2026-09-03 2
hostname i49.xyz 2026-09-03 2
hostname 9r.re 2026-09-03 1
hostname 2i.wf 2026-09-03 2
hostname k5j.one 2026-09-03 2
hostname qmpo.art 2026-09-03 2
hostname rx3.xyz 2026-09-03 2
hostname glnj.nl 2026-09-03 2

Detection coverage

  • 912 Sigma rules

Malware & tools used

  • Security Software Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • Web Service (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Inter-Process Communication (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Regsvr32 (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Hijack Execution Flow (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Domains (attack-pattern)
  • DLL (attack-pattern)
  • Process Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Component Object Model (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

  • 2023 Increased Truebot Activity (campaign)

Reports & references

  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • silentpush.com — Socgholish (report)
  • thehackernews.com — Microsoft Links Raspberry Robin Usb (report)
  • Cisco Talos — Breaking The Silence Recent Truebot Activity (report)
  • bleepingcomputer.com — Microsoft Links Raspberry Robin Worm To Clop Ransomware Attacks (report)
  • securityintelligence.com — Raspberry Robin Worm Dridex Malware (report)
  • Palo Alto Unit 42 — Unsigned Dlls (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Raspberry Robin (report)
  • Trend Micro — Raspberry Robin Malware Targets Telecom Governments (report)
  • research.checkpoint.com — Raspberry Robin Keeps Riding The Wave Of Endless 1 Days (report)
  • research.checkpoint.com — Raspberry Robin Anti Evasion How To Exploit Analysis (report)
  • zscaler.com — Unraveling Raspberry Robin S Layers Analyzing Obfuscation Techniques And (report)
  • harfanglab.io — Raspberry Robin And Its New Anti Emulation Trick (report)
  • securityjoes.com — Raspberry Robin Detected Itw Targeting Insurance Financial Institutes In Europe (report)
  • darktrace.com — The Early Bird Catches The Worm Darktraces Hunt For Raspberry Robin (report)
  • huntress.com — Evolution Of Usb Borne Malware Raspberry Robin (report)
  • blogs.cisco.com — Raspberry Robin Highly Evasive Worm Spreads Over External Disks (report)
  • decoded.avast.io — Raspberry Robins Roshtyak A Little Lesson In Trickery (report)
  • redcanary.com — Raspberry Robin (report)
  • cybereason.com — Threat Alert Raspberry Robin Worm Abuses Windows Installer And Qnap Devices (report)
  • MITRE ATT&CK — S1130 (report)
  • redcanary.com — Raspberry Robin (report)
  • threatresearch.ext.hp.com — Raspberry Robin Now Spreading Through Windows Script Files (report)
  • Trend Micro — Raspberry Robin Malware Targets Telecom Governments (report)

External references