logo

All About Raspberry Robin's Botnet Second Life

ID: 4a33147b-314e-560d-bb1b-97f32454cdc4

STIX ID: report--4a33147b-314e-560d-bb1b-97f32454cdc4

Feed Name: Sekoia.com

Threat Score
76/100

Date Published: 2023-01-10

Date Updated: 2026-07-20

...
...

Raspberry Robin is a USB-distributed worm/botnet that uses malicious LNK files to invoke msiexec and download MSI payloads hosted on compromised QNAP NAS instances; the botnet has multi-layered infrastructure (hundreds of domains, QNAP first-level forwarders and VPS proxies), has been used to deploy secondary malware (e.g., SocGholish, Bumblebee, IcedID) which can lead to lateralization and hands-on-keyboard ransomware, and is resilient due to frequently changing domain resolutions and potential for repurposing by other actors — Sekoia documents sinkholing, a partial takedown, and ongoing monitoring recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.