Raspberry Robin, also known as LNK Worm and QNAP Worm, is a Windows malware family that evolved from a USB-propagating worm into a malware loader and initial-access distribution platform. First observed in September 2021, it spreads through infected removable media and shared folders using malicious Windows shortcuts. Delivery has also been observed through archives and ISO images. Its infection chain abuses legitimate Windows utilities to download and execute malicious installer packages and DLL payloads, with compromised QNAP NAS devices used as staging infrastructure.
Raspberry Robin establishes persistence through scheduled tasks and startup registry mechanisms. It executes malicious code through trusted Windows utilities, uses DLL side-loading with legitimate signed executables, and injects code into legitimate processes. An embedded custom Tor client supports command-and-control communications and can execute inside a suspended process that is resumed after injection. The malware employs extensive multilayer obfuscation, security-software discovery, and anti-analysis checks. Some variants expose a decoy payload when sandboxing or analysis tools are detected while concealing the real payload. Privilege-escalation mechanisms include User Account Control bypass through Fodhelper and elevated COM objects.
Raspberry Robin has delivered Truebot, SocGholish, IcedID, Bumblebee, FlawedGrace, and Cobalt Strike, and has supported intrusion chains involving Clop and LockBit ransomware. Its activity has intersected with campaigns associated with Evil Corp, Silence, and Lace Tempest; these operational associations do not establish a single author or exclusive operator. Affected organizations span government, telecommunications, financial services, manufacturing, industrial, and service-provider sectors. Infections have been observed internationally, including Europe, the United States, Latin America, and Australia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cyber threat actors have shifted tactics, exploiting, in observable manner, a remote code execution vulnerability (CVE-2022-31199) in Netwrix Auditor. Through exploitation of this CVE, cyber threat actors gain initial access, as well as the ability to move laterally within the compromised network.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files. | An interesting observation we discovered while tracking these intrusion sets, and malware was that Water Asena (Evil Corp) had been exploiting ZDI-CAN-25373 in their Raspberry Robin campaigns.
CVE-2021-1732 is a win32k window object type confusion leading to an OOB (out-of-bounds) write. It was used as a 0-day in the wild by Bitter APT and written by Moses – also known as Exodus Intelligence. CVE-2021-1732 runs on Windows 10, with the targeted build number range being from 16353 to 19042. For the second exploit, it also checks if the package KB4601319 of the patch is present. | During the last year, Raspberry Robin has evolved to be one of the most distributed malware currently active. During this time, it is likely to be used by many actors to distribute their own malware such as IcedID, Clop ransomware and more.
CVE-2020-1054 is Win32k Elevation of Privilege Vulnerability reported by Check Point Research. The vulnerability is out of bounds write in win32k and it was used by different Exploit kits in the past. The exploit is only used by Raspberry Robin on Windows 7 systems where the revision number is not higher than 24552. | During the last year, Raspberry Robin has evolved to be one of the most distributed malware currently active. During this time, it is likely to be used by many actors to distribute their own malware such as IcedID, Clop ransomware and more.
"Raspberry Robin has added a new local privilege escalation (LPE) exploit (CVE-2024-38196) to gain elevated privileges on targeted systems."
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Raspberry Robin is a highly elusive worm-turned-loader that targets Microsoft Windows environments.
Raspberry Robin is a highly elusive worm-turned-loader that targets Microsoft Windows environments.
Lace Tempest "has been linked to GoAnywhere attacks and Raspberry Robin infection."
An interesting observation we discovered while tracking these intrusion sets, and malware was that Water Asena (Evil Corp) had been exploiting ZDI-CAN-25373 in their Raspberry Robin campaigns.
Microsoft says a threat group tracked as DEV-0950 used Clop ransomware to encrypt the network of a victim previously infected with the Raspberry Robin worm.
Microsoft on Friday disclosed a potential connection between the Raspberry Robin USB-based worm and an infamous Russian cybercrime group tracked as Evil Corp. Raspberry Robin, also called QNAP Worm, is known to spread from a compromised system via infected USB devices containing a malicious .LNK file to other devices in the target network.
42 distinct techniques documented for this family, organized by ATT&CK tactic.
66 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
95 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lace Tempest "has been linked to GoAnywhere attacks and Raspberry Robin infection."
Named malware infection historically linked to Lace Tempest; the content provides no further behavioral details.
Raspberry Robin is referenced as the malware used in campaigns by Water Asena (Evil Corp) that exploited the ZDI-CAN-25373 Windows shortcut vulnerability.
A malware family spread through infected removable media such as USB drives and often used to provide initial access for ransomware operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.