Raspberry Robin
MITRE ATT&CK: S1130 View on attack.mitre.org
Aliases: LINK_MSIEXEC, QNAP-Worm, RaspberryRobin, Raspberry Robin
- First seen
- 2021-09-01 00:00:00
- Malware type
- worm, loader, dropper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 322 (279 malicious)
- Last IoC activity
- 2026-09-02 00:35:05
- Profile updated
- 2026-07-07 13:08:30
Targeted industries: defense-and-aerospace financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee. The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak." The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.
Recent IoC activity
279 malicious indicators in Maltiverse are attributed to Raspberry Robin (S1130). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | 27o.nl | 2026-09-03 | 2 |
| hostname | 8t.pm | 2026-09-03 | 4 |
| hostname | zk.qa | 2026-09-03 | 1 |
| hostname | 1j4.xyz | 2026-09-03 | 2 |
| hostname | 4k1.xyz | 2026-09-03 | 2 |
| hostname | eznb.net | 2026-09-03 | 2 |
| hostname | vqdn.net | 2026-09-03 | 2 |
| hostname | lgf.pw | 2026-09-03 | 2 |
| hostname | soft.ac | 2026-09-03 | 1 |
| hostname | egso.net | 2026-09-03 | 2 |
| hostname | 5kx.me | 2026-09-03 | 2 |
| hostname | l5k.xyz | 2026-09-03 | 2 |
| hostname | as3.biz | 2026-09-03 | 2 |
| hostname | i49.xyz | 2026-09-03 | 2 |
| hostname | 9r.re | 2026-09-03 | 1 |
| hostname | 2i.wf | 2026-09-03 | 2 |
| hostname | k5j.one | 2026-09-03 | 2 |
| hostname | qmpo.art | 2026-09-03 | 2 |
| hostname | rx3.xyz | 2026-09-03 | 2 |
| hostname | glnj.nl | 2026-09-03 | 2 |
Detection coverage
- 912 Sigma rules
Malware & tools used
- Security Software Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Information Discovery (attack-pattern)
- Software Packing (attack-pattern)
- Web Service (attack-pattern)
- Execution Guardrails (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Inter-Process Communication (attack-pattern)
- Non-Standard Port (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Regsvr32 (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Hijack Execution Flow (attack-pattern)
- Masquerade File Type (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Web Protocols (attack-pattern)
- Process Hollowing (attack-pattern)
- Domains (attack-pattern)
- DLL (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Component Object Model (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
- 2023 Increased Truebot Activity (campaign)
Reports & references
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- silentpush.com — Socgholish (report)
- thehackernews.com — Microsoft Links Raspberry Robin Usb (report)
- Cisco Talos — Breaking The Silence Recent Truebot Activity (report)
- bleepingcomputer.com — Microsoft Links Raspberry Robin Worm To Clop Ransomware Attacks (report)
- securityintelligence.com — Raspberry Robin Worm Dridex Malware (report)
- Palo Alto Unit 42 — Unsigned Dlls (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Raspberry Robin (report)
- Trend Micro — Raspberry Robin Malware Targets Telecom Governments (report)
- research.checkpoint.com — Raspberry Robin Keeps Riding The Wave Of Endless 1 Days (report)
- research.checkpoint.com — Raspberry Robin Anti Evasion How To Exploit Analysis (report)
- zscaler.com — Unraveling Raspberry Robin S Layers Analyzing Obfuscation Techniques And (report)
- harfanglab.io — Raspberry Robin And Its New Anti Emulation Trick (report)
- securityjoes.com — Raspberry Robin Detected Itw Targeting Insurance Financial Institutes In Europe (report)
- darktrace.com — The Early Bird Catches The Worm Darktraces Hunt For Raspberry Robin (report)
- huntress.com — Evolution Of Usb Borne Malware Raspberry Robin (report)
- blogs.cisco.com — Raspberry Robin Highly Evasive Worm Spreads Over External Disks (report)
- decoded.avast.io — Raspberry Robins Roshtyak A Little Lesson In Trickery (report)
- redcanary.com — Raspberry Robin (report)
- cybereason.com — Threat Alert Raspberry Robin Worm Abuses Windows Installer And Qnap Devices (report)
- MITRE ATT&CK — S1130 (report)
- redcanary.com — Raspberry Robin (report)
- threatresearch.ext.hp.com — Raspberry Robin Now Spreading Through Windows Script Files (report)
- Trend Micro — Raspberry Robin Malware Targets Telecom Governments (report)
External references
- mitre-attack — S1130
- TrendMicro RaspberryRobin 2022
- Avast RaspberryRobin 2022
- RedCanary RaspberryRobin 2022
- Microsoft RaspberryRobin 2022
- HP RaspberryRobin 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy