Raspberry Robin
Raspberry Robin is an activity cluster and long-running malware operation active since 2019. It is described as using a worm spread by infected external or USB drives, with infections beginning from a malicious shortcut file on the device. The shortcut launches msiexec.exe to retrieve a malicious DLL from remote command-and-control infrastructure, after which the malware establishes persistence via a scheduled task. Reporting also describes Raspberry Robin DLLs as having scrambled names in random ProgramData or AppData subfolders and being loaded with rundll32.exe or regsvr32.exe. Raspberry Robin has been associated with DLL loading activity and abuse of Windows Installer, and one reference notes tradecraft involving shell32.dll. Its command-and-control infrastructure has been described as using newly registered domains with only a few characters, including three-character patterns and uncommon two-letter TLDs such as .wf, .pm, and .re; one cited example is v0[.]cx. Another report tied roughly 200 unique domains to the operation and described Fast Flux behavior. The content also states that Raspberry Robin malware has exploited a Windows CLFS vulnerability for privilege escalation. Known alias in the provided content: raspberry_robin.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-running malware operation spreading via infected USB drives; infrastructure characterized by patterned domains, uncommon TLDs, and fast-flux behavior to resist tracking and takedown.
Referenced as an example of an actor/campaign that leverages a Windows system DLL (shell32.dll) in conjunction with LOLBIN-style execution patterns (context: rundll32 detections/whitelisting).
Activity cluster spreading via external drives and using Windows Installer to download malicious files.
An activity cluster that spreads via external drives and uses Windows Installer to fetch malicious payloads.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.