logo

Raspberry Robin Malware in 2025: From USB Worm to Elite Initial Access Broker

ID: f98286af-fc76-526a-a1bf-04b9d3f1a56d

STIX ID: report--f98286af-fc76-526a-a1bf-04b9d3f1a56d

Feed Name: Resources-2

Threat Score
85/100

Date Published: 2025-08-13

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

Raspberry Robin (aka Roshtyak, tracked as Storm-0856) is a sophisticated Windows malware family that has progressed from USB worm behavior to a large-scale initial-access broker delivering ransomware, loaders, and infostealers. The report describes diverse distribution methods (USB LNKs, phishing, malvertising, Discord CDN), DLL side‑loading and WSF-based loaders with anti-analysis checks, living‑off‑the‑land execution, privilege escalation, PAExec-based lateral movement, and a resilient C2 built on fast‑flux DNS, compromised IoT/NAS relays and Tor; it also lists detection opportunities and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.