Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Raspberry Robin

Raspberry Robin

TLP:CLEAR
Family

AI Analysis

· 2 hours ago

Executive Summary

Raspberry Robin is a Windows initial access Trojan that spreads through malicious USB shortcuts. It downloads a DLL loader (Roshtyak) that persists on the host and serves as a staging ground for advanced payloads, including ransomware and Cobalt Strike. The campaign is attributed to Storm‑0856 and has been used across diverse industries since 2021.

Enhanced Description

Raspberry Robin is a Windows‑based initial access Trojan first observed in September 2021 and remained active into early 2024. The campaign relies exclusively on compromised USB devices that contain a malicious LNK shortcut; when the user activates the link, the payload contacts a remote hosting server to download additional components for execution. This technique allows Raspberry Robin to bypass typical network perimeter defenses while exploiting human behavior—leveraging removable media introduced by insiders or socially engineered victims. Once executed, the malware installs a secondary DLL component called "Roshtyak", which acts as a loader and persistence agent. It can modify registry entries, set scheduled tasks, and masquerade as legitimate system processes to maintain continued access. The attacker’s toolset is modular; Raspberry Robin is frequently used as an entry point for more destructive payloads such as SocGholish, IcedID, Bumblebee, or even commercial exploitation frameworks like Cobalt Strike. By off‑loading the heavy payloads to post‑exploitation modules, the initial infection remains lightweight and difficult to detect. The threat actor behind this campaign has been identified by multiple vendors as Storm‑0856. Analysts have noted that Raspberry Robin’s widespread use across various industries—including finance, healthcare, and manufacturing—underscores its role in a broader strategy of supply‑chain infiltration and staged delivery of malicious code. Given its simple dropper structure coupled with the ability to spawn sophisticated adversary frameworks, this malware represents both an economical and effective vector for large‑scale compromises. Overall, Raspberry Robin demonstrates how attackers leverage everyday peripherals to gain footholds, use lightweight loaders to establish persistence, and then pivot to more lethal tools as part of a multi‑stage attack chain.

Key Capabilities

  • Initial access via malicious USB LNK files
  • Downloader that fetches remote payloads
  • Installs Roshtyak DLL as persistence mechanism
  • Creates scheduled tasks or modifies registry for boot‑time execution
  • Modules capable of launching additional threats such as SocGholish, Cobalt Strike, IcedID, and Bumblebee

ATT&CK Techniques

T1059
T1105
T1053
T1074
T1060

Recommended Actions

  • Deploy USB device control solutions to restrict removable media use
  • Configure group policies to block execution of LNK files from untrusted drives
  • Implement endpoint detection & response sensors that flag Roshtyak DLL loads
  • Monitor for anomalous outbound connections to known malicious download URLs
  • Maintain up‑to‑date malware database and signature feeds for downloader patterns
  • Enforce least privilege and regularly patch Windows systems

Suggested Tags

ransomware
initial-access
usb-based-infection
downloader
payload-delivery
trojan
cobalt-strike
socgholish
icedid

Confidence Assessment

The available data provides a clear picture of Raspberry Robin’s initial access vector and its role as a dropper for more advanced payloads. However, detailed technical insight into persistence mechanics, command‑and‑control infrastructure, and full execution chain remains limited; further reverse engineering would be required to fill these gaps fully.

Description

Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.(Citation: TrendMicro RaspberryRobin 2022)(Citation: RedCanary RaspberryRobin 2022)(Citation: HP RaspberryRobin 2024) The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."(Citation: Avast RaspberryRobin 2022) The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as <code>Storm-0856</code> by some vendors.(Citation: Microsoft RaspberryRobin 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.