Raspberry Robin Analysis
ID: 36b0450d-c9a1-597a-b12f-603f01cb6ec1
STIX ID: report--36b0450d-c9a1-597a-b12f-603f01cb6ec1
Feed Name: Zscaler Security Research Blog
This report provides a comprehensive technical analysis of the Raspberry Robin malware: its multi-layered loader and core, extensive anti-analysis and obfuscation methods, decoy payload logic, persistence and obscure registry modification techniques, lateral propagation via RDP and SMB (using PsExec/PAExec and IExpress), embedded TOR client for C2 communications, capability to download and execute arbitrary payloads, and use of local privilege escalation and exploitation (including CVE-2024-26229 and CVE-2021-31969) to expand capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
