Evolution of USB-Borne Malware, Raspberry Robin
ID: 117f8e0e-907b-5f58-a35c-db0415491462
STIX ID: report--117f8e0e-907b-5f58-a35c-db0415491462
Feed Name: Huntress Blog
Huntress observed Raspberry Robin USB-worm activity across its customer base and provides a concise analysis of the infection chain: users open malicious Windows shortcut (.LNK) files on infected USB devices, which run obfuscated msiexec commands to download payloads (commonly over port 8080 from short domains) and persist by re-creating values under the user's RunOnce registry key; the report includes example command lines, observed IOCs, and an August 2023 failed infection timeline demonstrating detection by Managed EDR and Microsoft Defender.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
