Roshtyak

Malware type
backdoor
Profile updated
2026-07-07 13:08:25

Context

A DLL backdoor distributed by Raspberry Robin. According to Avast Decoded, Roshtyak belongs to one of the best-protected malware strains they have ever seen.

Reports & references

  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • Palo Alto Unit 42 — Unsigned Dlls (report)
  • Trend Micro — Raspberry Robin Malware Targets Telecom Governments (report)
  • zscaler.com — Unraveling Raspberry Robin S Layers Analyzing Obfuscation Techniques And (report)
  • decoded.avast.io — Raspberry Robins Roshtyak A Little Lesson In Trickery (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Roshtyak (report)

External references