Raspberry Robin is a long-running malware activity cluster and worm-based distribution ecosystem active since at least 2019. It is best known for spreading through infected removable drives via malicious shortcut files and for using Windows Installer to retrieve additional malicious components. Raspberry Robin has become one of the most prevalent malware clusters observed in enterprise telemetry and is widely assessed to function as an initial-access and malware-delivery platform that can enable follow-on payloads from multiple actors, including commodity malware and ransomware operations. A core Raspberry Robin component is the Roshtyak DLL backdoor, a heavily obfuscated and anti-analysis-focused payload packed through numerous layers. Raspberry Robin and Roshtyak employ extensive defense-evasion measures, including anti-debugging, anti-virtualization, anti-sandbox, anti-emulation, hidden threads, exception-based checks, command-line wiping, deceptive fake-stage unpacking, and manipulation of security controls. Observed persistence mechanisms include RunOnce or RunOnceEx abuse and scheduled-task creation. The malware has also been observed modifying Microsoft Defender exclusions and removing or interfering with execution-monitoring mechanisms. Operationally, Raspberry Robin serves as a downloader and post-compromise platform. It profiles infected hosts, communicates with command-and-control infrastructure, retrieves additional payloads, and can exfiltrate victim information. Reported follow-on activity includes delivery of malware such as IcedID and ransomware-associated tooling including Clop-related payloads. Roshtyak has also been observed attempting privilege escalation through embedded local exploit code for CVE-2020-1054, CVE-2021-1732, and later reporting indicates exploitation of a Windows CLFS vulnerability. Post-exploitation behavior includes process injection, use of Tor-based communications, and lateral movement opportunities through PsExec when elevated or domain-admin access is available. Raspberry Robin is notable for broad use of LOLBins and signed Windows utilities, especially msiexec.exe, rundll32.exe, and regsvr32.exe, as well as scrambled DLL naming and execution from user-writable directories. It has also been associated with DLL-loading tradecraft and worm-like propagation via external drives. Although Raspberry Robin has been linked in some reporting to downstream criminal operations and possible pre-ransomware activity, the cluster is most reliably characterized as a highly prevalent malware distribution and access platform rather than a single clearly attributed nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for similar MSIEXEC-based behavior; not the focus of the article.
Long-running malware operation spreading via infected USB drives; infrastructure characterized by patterned domains, uncommon TLDs, and fast-flux behavior to resist tracking and takedown.
Referenced as an example of an actor/campaign that leverages a Windows system DLL (shell32.dll) in conjunction with LOLBIN-style execution patterns (context: rundll32 detections/whitelisting).
Activity cluster spreading via external drives and using Windows Installer to download malicious files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.