Raspberry Robin: A global USB malware campaign providing access to ransomware operators
ID: 8ba5357f-55c1-54ba-8b3a-3ef5383a847a
STIX ID: report--8ba5357f-55c1-54ba-8b3a-3ef5383a847a
Feed Name: BushidoToken Blog
This blog summarizes an active, global USB-borne malware campaign named Raspberry Robin that spreads via malicious LNK files on USB drives (potentially originating from infected printers/print shops), uses compromised NAS devices (QNAP/Acrobox) as C2 infrastructure, and acts as a precursor to high-profile ransomware via loaders like IcedID, Bumblebee, SocGholish and Truebot; it also provides detection advice (Splunk SPL rules), YARA hunting methodology and a table of IOCs (SHA256s, filenames, embedded domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
