logo

Raspberry Robin Malware Upgrades with Discord Spread and New Exploits

ID: d970000f-9f26-567b-94fb-eaa2c599a2bb

STIX ID: report--d970000f-9f26-567b-94fb-eaa2c599a2bb

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Raspberry Robin (aka QNAP worm), attributed to Storm-0856, has been observed actively incorporating one-day/zero-day exploits (e.g., CVE-2023-36802, CVE-2023-29360) for privilege escalation, improving anti-analysis/obfuscation, changing lateral movement to PAExec, and using randomized Tor onion addresses for C2; operators appear to obtain exploits from dark web sellers, enabling rapid use of newly disclosed vulnerabilities and sustaining large waves of attacks that facilitate additional payloads including ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.