ATT&CKReferencesRedCanary RaspberryRobin 2022

RedCanary RaspberryRobin 2022

Lauren Podber and Stef Rand. (2022, May 5). Raspberry Robin gets the worm early. Retrieved May 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRaspberry Robin

Raspberry Robin uses mixed-case letters for filenames and commands to evade detection.

T1036.008
Masquerade File Type
MalwareRaspberry Robin

Raspberry Robin has historically been delivered via infected USB drives containing a malicious LNK object masquerading as a legitimate folder.

T1059.003
Windows Command Shell
MalwareRaspberry Robin

Raspberry Robin uses cmd.exe to read and execute a file stored on an infected USB device as part of initial installation.

T1071
Application Layer Protocol
MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1071.001
Web Protocols
MalwareRaspberry Robin

Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution.

T1091
Replication Through Removable Media
MalwareRaspberry Robin

Raspberry Robin has historically used infected USB media to spread to new victims.

T1105
Ingress Tool Transfer
MalwareRaspberry Robin

Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's %AppData% folder.

T1218.007
Msiexec
MalwareRaspberry Robin

Raspberry Robin uses msiexec.exe for post-installation communication to command and control infrastructure. Msiexec.exe is executed referencing a remote resource for second-stage payload retrieval and execution.

T1218.008
Odbcconf
MalwareRaspberry Robin

Raspberry Robin uses the Windows utility odbcconf.exe to execute malicious commands, using the regsvr flag to execute DLLs and bypass application control mechanisms that are not monitoring for odbcconf.exe abuse.

T1218.010
Regsvr32
MalwareRaspberry Robin

Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.

T1218.011
Rundll32
MalwareRaspberry Robin

Raspberry Robin uses rundll32 execution without any command line parameters to contact command and control infrastructure, such as IP addresses associated with Tor nodes.

T1548.002
Bypass User Account Control
MalwareRaspberry Robin

Raspberry Robin will use the legitimate Windows utility fodhelper.exe to run processes at elevated privileges without requiring a User Account Control prompt.

T1571
Non-Standard Port
MalwareRaspberry Robin

Raspberry Robin will communicate via HTTP over port 8080 for command and control traffic.

T1583.001
Domains
MalwareRaspberry Robin

Raspberry Robin uses newly-registered domains containing only a few characters for command and controll purposes, such as "v0[.]cx".

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.