Executive Summary
Raspberry Robin is a Windows initial access Trojan that spreads through malicious USB shortcuts. It downloads a DLL loader (Roshtyak) that persists on the host and serves as a staging ground for advanced payloads, including ransomware and Cobalt Strike. The campaign is attributed to Storm‑0856 and has been used across diverse industries since 2021.
Enhanced Description
Raspberry Robin is a Windows‑based initial access Trojan first observed in September 2021 and remained active into early 2024. The campaign relies exclusively on compromised USB devices that contain a malicious LNK shortcut; when the user activates the link, the payload contacts a remote hosting server to download additional components for execution. This technique allows Raspberry Robin to bypass typical network perimeter defenses while exploiting human behavior—leveraging removable media introduced by insiders or socially engineered victims. Once executed, the malware installs a secondary DLL component called "Roshtyak", which acts as a loader and persistence agent. It can modify registry entries, set scheduled tasks, and masquerade as legitimate system processes to maintain continued access. The attacker’s toolset is modular; Raspberry Robin is frequently used as an entry point for more destructive payloads such as SocGholish, IcedID, Bumblebee, or even commercial exploitation frameworks like Cobalt Strike. By off‑loading the heavy payloads to post‑exploitation modules, the initial infection remains lightweight and difficult to detect. The threat actor behind this campaign has been identified by multiple vendors as Storm‑0856. Analysts have noted that Raspberry Robin’s widespread use across various industries—including finance, healthcare, and manufacturing—underscores its role in a broader strategy of supply‑chain infiltration and staged delivery of malicious code. Given its simple dropper structure coupled with the ability to spawn sophisticated adversary frameworks, this malware represents both an economical and effective vector for large‑scale compromises. Overall, Raspberry Robin demonstrates how attackers leverage everyday peripherals to gain footholds, use lightweight loaders to establish persistence, and then pivot to more lethal tools as part of a multi‑stage attack chain.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a clear picture of Raspberry Robin’s initial access vector and its role as a dropper for more advanced payloads. However, detailed technical insight into persistence mechanics, command‑and‑control infrastructure, and full execution chain remains limited; further reverse engineering would be required to fill these gaps fully.
Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.(Citation: TrendMicro RaspberryRobin 2022)(Citation: RedCanary RaspberryRobin 2022)(Citation: HP RaspberryRobin 2024) The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."(Citation: Avast RaspberryRobin 2022) The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as <code>Storm-0856</code> by some vendors.(Citation: Microsoft RaspberryRobin 2022)