logo

Raspberry Robin Analysis

ID: 36b0450d-c9a1-597a-b12f-603f01cb6ec1

STIX ID: report--36b0450d-c9a1-597a-b12f-603f01cb6ec1

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report provides a comprehensive technical analysis of the Raspberry Robin malware: its multi-layered loader and core, extensive anti-analysis and obfuscation methods, decoy payload logic, persistence and obscure registry modification techniques, lateral propagation via RDP and SMB (using PsExec/PAExec and IExpress), embedded TOR client for C2 communications, capability to download and execute arbitrary payloads, and use of local privilege escalation and exploitation (including CVE-2024-26229 and CVE-2021-31969) to expand capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.