Microsoft warns Raspberry Robin malware is getting a lot sourer

The mysterious malware is no longer dormant, Microsoft says

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

The Raspberry Robin malware is being used to deliver all kinds of destructive code, includingransomware, to compromisedendpoints,Microsofthas warned.

It seems themalware, first discovered late in 2021, and whose endgame was unknown at the time, transformed into an infection service available to anyone with cash to pay.

Cybersecurity researchers from Microsoft have published a detailedblog postin which they describe Raspberry Robin as “part of a complex and interconnected malware ecosystem”, with links to other malware families and alternate infection methods.

Infection for hire

Infection for hire

Whoever is behind Raspberry Robin kept busy over these last couple of weeks, as according to Microsoft Defender for Endpoint data, almost 3,000 devices in 1,000 organizations have experienced at least one Raspberry Robin payload-related alert in the last 30 days.

Payloads differ, the company further explained, from FakeUpdates malware which led to possible EvilCorp activity, to IceID, Bumblebee, and Truebot. This is all July 2022.

In October 2022, though, Microsoft also spotted Raspberry Robin being used by FIN11 (AKA TA505, - the group behind the Dridex banking trojan and Locky ransomware). This activity led to Cobalt Strike hands-on-keyboard compromises, the company explained, sometimes with a Truebot infection in between the Raspberry Robin and Cobalt Strike stages. Following the Cobalt Strike beacon, the group deployed the Clop ransomware.

All things considered, Microsoft concluded that the group behind Raspberry Robin is taking payments to deploy various malware and ransomware to its victims’ endpoints.

Are you a pro? Subscribe to our newsletter

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Nasty Windows worm spreads to hundreds of networks via infected USB drives>This dangerous new malware is attacking Windows devices via infected USB drives>These are the best internet security suites out there

“Given the interconnected nature of the cybercriminal economy, it’s possible that the actors behind these Raspberry Robin-related malware campaigns—usually distributed through other means like malicious ads or email—are paying the Raspberry Robin operators for malware installs,” the report concludes.

Raspberry Robin wasfirst identifiedwhen researchers from Red Canary discovered a “cluster of malicious activity”. The malware is usually distributed offline, via infected USB drives. After analyzing an infected thumb drive, the researchers discovered that the worm spreads to new devices via a malicious .LNK file.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

This new phishing strategy utilizes GitHub comments to distribute malware

Should your VPN always be on?

The M4 Mac mini has removable, modular storage – and an important SSD upgrade