Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Raspberry Robin

126
Global rank
101 infographic chevron month
Month rank
91 infographic chevron week
Week rank

Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.

Trojan
Type
Unknown
Origin
1 September, 2021
First seen
17 September, 2026
Last seen

How to analyze Raspberry Robin with ANY.RUN

Type
Unknown
Origin
1 September, 2021
First seen
17 September, 2026
Last seen

IOCs

IP addresses
2.23.246.9
172.217.117.4
23.216.77.36
142.251.127.84
48.209.138.189
104.18.14.169
172.217.115.4
142.250.154.95
20.190.159.0
8.8.8.8
142.251.110.113
142.251.13.139
88.221.169.152
172.211.123.249
210.55.30.93
135.232.92.97
142.251.156.119
23.11.41.157
57.153.246.3
142.251.110.139
Hashes
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
807882f310ebf263f7b85b683add53970251d3cafb3b22ac3fce9923fb15ab35
7ba53fc9c7a8b57f4f9b01c6ba83b50e83d0662e52134d48a60195a910aa3d86
06ab381e06178f2a0062db9b1d069adf065c4ff00232426b8d70fa3ad7703a76
4c897707a45592774ffc4c65b207589efee2f1667798f96b4e37245047466e3e
dd9ce6b3ae599ee1a027bbd1e53c071cda2f136ee144a7a8597f20e53405a29e
b00a8ae348e6e4f12c3410ba71ed3547764432d21f737b51f7100e5ae7ff0bd3
93332c49fab1deb87dac6cb5d313900cb20e6e1ba928af128a1d549a44256f68
10c8ff7aa63c4a53d8737ff0d432ca406eea1f02b9c57122e155491498a71bd0
25aad5d4507e12952cc8acf3063ca5122c3d4dc28527365154e5c9ad5fe7cfea
5ee004095de29a46de16b78f9020dedfdb3cbe41d2b60ce9e01c6699823f6953
cae66ee75c139fd2f338478a56cd51ba8c0bd51daf931bb48ac88fae665566af
9f39ffafa25fdaff0b8f2dc2d48f89f3a302a496a6d343c7d346766c8a037ece
Domains
ajax.googleapis.com
go.microsoft.com
settings-win.data.microsoft.com
crl.microsoft.com
google.com
ecs.office.com
4.nz
www.google.com
safebrowsingohttpgateway.googleapis.com
client.wns.windows.com
www.microsoft.com
parking.1stdomains.nz
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
clientservices.googleapis.com
content-autofill.googleapis.com
activation-v2.sls.microsoft.com
optimizationguide-pa.googleapis.com
clients2.google.com
update.googleapis.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://clients2.google.com/time/1/current?cup2key=8:ff_ozxilnvsl8cx4teuwjeuphjpuh7w7mnf2rkq9wiw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://4.nz/
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://4.nz/
https://4.nz/favicon.ico
https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js
https://parking.1stdomains.nz/assets/parking.css
https://parking.1stdomains.nz/assets/images/flag.jpg
https://parking.1stdomains.nz/assets/images/logo-new.gif
https://parking.1stdomains.nz/assets/images/searchbar.jpg
https://parking.1stdomains.nz/assets/images/search.png
https://parking.1stdomains.nz/assets/images/nolimits.jpg
https://parking.1stdomains.nz/assets/images/overlay.png
https://parking.1stdomains.nz/assets/images/email.jpg
https://parking.1stdomains.nz/assets/images/expired.jpg
https://parking.1stdomains.nz/assets/images/footer.jpg
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1292
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1586
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3183
comments 0

What is Raspberry Robin malware?

Raspberry Robin is a worm malware that has been tracked since 2021. The malware has been used to target organizations across various industries and sectors, with finance, manufacturing, and government being particularly affected.

Initially, infections with Raspberry Robin appeared to lack a specific end goal. However, it soon began to distribute other malware, including the LockBit ransomware and SocGholish (FakeUpdates).

A notable characteristic of this threat is its utilization of compromised network-attached storage (NAS) devices from QNAP, as part of its infrastructure. Another distinctive feature of the malware is its exploitation of legitimate Windows commands, such as msiexec.exe and odbcconf.exe, to retrieve, deploy, and execute malicious DLLs.

Researchers have noted a connection between Raspberry Robin and the Dridex malware, a recognized banking trojan. It is likely that these two malicious programs have been operated by the same threat actor group.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Raspberry Robin execution process

To take a closer look at Raspberry Robin’s functionality, we can submit its sample for analysis to the ANY.RUN sandbox.

Raspberry Robin analysis in ANY.RUN Analysis of Raspberry Robin in ANY.RUN

Raspberry Robin is typically delivered through infected external disks or USB drives containing a Windows Shortcut file (.lnk). Upon connecting the infected USB device and launching the .lnk file, a command processor (cmd.exe) is initiated and executes a Microsoft Installer Executable (MSIExec).

This action ultimately downloads a payload from a compromised QNAP network-attached storage (NAS) device or a web server.

Raspberry Robin process graph in ANY.RUN Raspberry Robin process graph demonstrated by ANY.RUN sandbox

The payload is stored in the local AppData folder and executed using msiexec.exe, which activates the Raspberry Robin malware.

The malware communicates with command-and-control (C2) servers over the TOR network and is capable of downloading and executing additional payloads, including other malware families such as Cobalt Strike, IcedID, BumbleBee, and Truebot.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Raspberry Robin malware technical details

The malware often injects dozens of legitimate processes on the infected device, including dllhost.exe and rundll32.exe, which are then utilized to maintain command-and-control (C2) communication.

Some samples of the malware have been subjected to advanced obfuscation, packing, anti-debugging, and evasion mechanisms. One unique method involves downloading a fake payload after the threat detects a virtual environment. Other anti-VM techniques include identifying the system's Mac address and processor information. Learn more about how you can counter anti-VM techniques in a sandbox.

The malware can also detect common antivirus software, such as Avast and BitDefender, by checking if the system has active processes related to these programs.

Raspberry Robin establishes persistence on the system by adding registry keys and employing other techniques to ensure it runs automatically at startup. The malware can gain elevated privileges on the machine through a User Account Control bypass.

Once it gains persistence on the system, the malware may initiate connections to TOR nodes to communicate with its command-and-control (C2) server via TCP ports, such as 8080.

Raspberry Robin malware distribution methods

Since Raspberry Robin is a worm type of malware, it has the ability to self-replicate and spread without requiring human interaction. This malware has been spreading primarily through infected USB drives, which has allowed it to achieve a significant scale of distribution across numerous machines. As users unknowingly connect infected USB drives to their devices and execute the malicious files, the malware propagates to new systems, expanding its reach and potential impact.

In addition to infected USB drives, another vector of attack for Raspberry Robin may involve an archive distributed through Discord. It usually contains Oleview.exe, a legitimate Windows application, alongside a malicious .dll file. When a user extracts and launches Oleview.exe from the archive, it side-loads the malicious .dll file, leading to the infection.

Conclusion

Raspberry Robin is still an active threat, which means that thousands of systems worldwide are at risk of being targeted by it. To effectively counter Raspberry Robin, implement strong security policies, maintain updated software, and provide ongoing security awareness training. Using a quick and effective sandbox should be one of the core elements of this strategy.

ANY.RUN's cloud sandbox provides many benefits for examining malware, such as:

  • Quickly finding threats in files and URLs (in less than 40 seconds)
  • Directly interacting with samples and the system for a realistic analysis
  • Customizing Windows and Linux virtual machines to fit your needs
  • Generating detailed reports that explain the identified threats and their impact
  • Showing all harmful activities related to the network, registry, files, and processes

Create your FREE ANY.RUN account today!

HAVE A LOOK AT

LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Keylogger screenshot
Keylogger
keylogger
A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More