logo

Raspberry Robin: A global USB malware campaign providing access to ransomware operators

ID: 8ba5357f-55c1-54ba-8b3a-3ef5383a847a

STIX ID: report--8ba5357f-55c1-54ba-8b3a-3ef5383a847a

Feed Name: BushidoToken Blog

Threat Score
75/100

Date Published: 2023-05-03

Date Updated: 2026-06-12

...
...

This blog summarizes an active, global USB-borne malware campaign named Raspberry Robin that spreads via malicious LNK files on USB drives (potentially originating from infected printers/print shops), uses compromised NAS devices (QNAP/Acrobox) as C2 infrastructure, and acts as a precursor to high-profile ransomware via loaders like IcedID, Bumblebee, SocGholish and Truebot; it also provides detection advice (Splunk SPL rules), YARA hunting methodology and a table of IOCs (SHA256s, filenames, embedded domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.