logo

Evolution of USB-Borne Malware, Raspberry Robin

ID: 117f8e0e-907b-5f58-a35c-db0415491462

STIX ID: report--117f8e0e-907b-5f58-a35c-db0415491462

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress observed Raspberry Robin USB-worm activity across its customer base and provides a concise analysis of the infection chain: users open malicious Windows shortcut (.LNK) files on infected USB devices, which run obfuscated msiexec commands to download payloads (commonly over port 8080 from short domains) and persist by re-creating values under the user's RunOnce registry key; the report includes example command lines, observed IOCs, and an August 2023 failed infection timeline demonstrating detection by Managed EDR and Microsoft Defender.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.