ATT&CKReferencesTrendMicro RaspberryRobin 2022

TrendMicro RaspberryRobin 2022

Christopher So. (2022, December 20). Raspberry Robin Malware Targets Telecom, Governments. Retrieved May 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareRaspberry Robin

Raspberry Robin contains multiple payloads that are packed for defense evasion purposes and unpacked on runtime.

T1033
System Owner/User Discovery
MalwareRaspberry Robin

Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges.

T1036.004
Masquerade Task or Service
MalwareRaspberry Robin

Raspberry Robin will execute its payload prior to initializing command and control traffic by impersonating one of several legitimate program names such as dllhost.exe, regsvr32.exe, or rundll32.exe.

T1047
Windows Management Instrumentation
MalwareRaspberry Robin

Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package.

T1055.012
Process Hollowing
MalwareRaspberry Robin

Raspberry Robin will execute a legitimate process, then suspend it to inject code for a Tor client into the process, followed by resumption of the process to enable Tor client execution.

T1057
Process Discovery
MalwareRaspberry Robin

Raspberry Robin can identify processes running on the victim machine, such as security software, during execution.

T1071
Application Layer Protocol
MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1091
Replication Through Removable Media
MalwareRaspberry Robin

Raspberry Robin has historically used infected USB media to spread to new victims.

T1140
Deobfuscate/Decode Files or Information
MalwareRaspberry Robin

Raspberry Robin contains several layers of obfuscation to hide malicious code from detection and analysis.

T1218.007
Msiexec
MalwareRaspberry Robin

Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution.

T1480
Execution Guardrails
MalwareRaspberry Robin

Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script.

T1497
Virtualization/Sandbox Evasion
MalwareRaspberry Robin

Raspberry Robin contains real and fake second-stage payloads following initial execution, with the real payload only delivered if the malware determines it is not running in a virtualized environment.

T1518.001
Security Software Discovery
MalwareRaspberry Robin

Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky.

T1547.001
Registry Run Keys / Startup Folder
MalwareRaspberry Robin

Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce
{random value name} = “rundll32 shell32 ShellExec_RunDLLA REGSVR /u /s “{dropped copy path and file name}””
.

T1548
Abuse Elevation Control Mechanism
MalwareRaspberry Robin

Raspberry Robin implements a variation of the ucmDccwCOMMethod technique abusing the Windows AutoElevate backdoor to bypass UAC while elevating privileges.

T1559
Inter-Process Communication
MalwareRaspberry Robin

Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory.

T1559.001
Component Object Model
MalwareRaspberry Robin

Raspberry Robin creates an elevated COM object for CMLuaUtil and uses this to set a registry value that points to the malicious LNK file during execution.

T1574
Hijack Execution Flow
MalwareRaspberry Robin

Raspberry Robin will drop a copy of itself to a subfolder in %Program Data% or %Program Data%\\Microsoft\\ to attempt privilege elevation and defense evasion if not running in Session 0.

T1622
Debugger Evasion
MalwareRaspberry Robin

Raspberry Robin leverages anti-debugging mechanisms through the use of ThreadHideFromDebugger.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.