logo

Raspberry Robin malware evolves with early access to Windows exploits

ID: 07e6c165-162a-54de-988b-e328c252a9ae

STIX ID: report--07e6c165-162a-54de-988b-e328c252a9ae

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Recent Raspberry Robin campaigns have become stealthier and more capable, using one-day local privilege escalation exploits (notably CVE-2023-36802 and CVE-2023-29360) shortly after public disclosure to gain SYSTEM-level access. The worm spreads via removable media and malicious archives distributed through Discord, side-loads malicious DLLs, leverages PAExec for lateral movement, implements new anti-analysis/evasion techniques (ETW patching, API-hook checks, shutdown prevention), and uses Tor domains and Discord URLs for C2 and delivery; Check Point provides IoCs including hashes and domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.