All About Raspberry Robin's Botnet Second Life
ID: 4a33147b-314e-560d-bb1b-97f32454cdc4
STIX ID: report--4a33147b-314e-560d-bb1b-97f32454cdc4
Feed Name: Sekoia.com
Raspberry Robin is a USB-distributed worm/botnet that uses malicious LNK files to invoke msiexec and download MSI payloads hosted on compromised QNAP NAS instances; the botnet has multi-layered infrastructure (hundreds of domains, QNAP first-level forwarders and VPS proxies), has been used to deploy secondary malware (e.g., SocGholish, Bumblebee, IcedID) which can lead to lateralization and hands-on-keyboard ransomware, and is resilient due to frequently changing domain resolutions and potential for repurposing by other actors — Sekoia documents sinkholing, a partial takedown, and ongoing monitoring recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
