Patrick Schläpfer . (2024, April 10). Raspberry Robin Now Spreading Through Windows Script Files. Retrieved May 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareRaspberry Robin | Raspberry Robin can identify processes running on the victim machine, such as security software, during execution. |
| T1059 Command and Scripting Interpreter |
MalwareRaspberry Robin | Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution. |
| T1070.004 File Deletion |
MalwareRaspberry Robin | Raspberry Robin can delete its initial delivery script from disk during execution. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071.001 Web Protocols |
MalwareRaspberry Robin | Raspberry Robin uses outbound HTTP requests containing victim information for retrieving second stage payloads. Variants of Raspberry Robin can download archive files (such as 7-Zip files) via the victim web browser for second stage execution. |
| T1082 System Information Discovery |
MalwareRaspberry Robin | Raspberry Robin performs several system checks as part of anti-analysis mechanisms, including querying the operating system build number, processor vendor and type, video controller, and CPU temperature. |
| T1083 File and Directory Discovery |
MalwareRaspberry Robin | Raspberry Robin will check to see if the initial executing script is located on the user's Desktop as an anti-analysis check. |
| T1102 Web Service |
MalwareRaspberry Robin | Raspberry Robin second stage payloads can be hosted as RAR files, containing a malicious EXE and DLL, on Discord servers. |
| T1105 Ingress Tool Transfer |
MalwareRaspberry Robin | Raspberry Robin retrieves its second stage payload in a variety of ways such as through msiexec.exe abuse, or running the curl command to download the payload to the victim's |
| T1480 Execution Guardrails |
MalwareRaspberry Robin | Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script. |
| T1497.001 System Checks |
MalwareRaspberry Robin | Raspberry Robin performs a variety of system environment checks to determine if it is running in a virtualized or sandboxed environment, such as querying CPU temperature information and network card MAC address information. |
| T1518.001 Security Software Discovery |
MalwareRaspberry Robin | Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky. |
| T1574.001 DLL |
MalwareRaspberry Robin | Raspberry Robin can use legitimate, signed EXE files paired with malicious DLL files to load and run malicious payloads while bypassing defenses. |
| T1583.008 Malvertising |
MalwareRaspberry Robin | Raspberry Robin variants have been delivered via malicious advertising items that, when interacted with, download a malicious archive file containing the initial payload, hosted on services such as Discord. |
| T1685 Disable or Modify Tools |
MalwareRaspberry Robin | Raspberry Robin can add an exception to Microsoft Defender that excludes the entire main drive from anti-malware scanning to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.