Raspberry Robin Malware Upgrades with Discord Spread and New Exploits
ID: d970000f-9f26-567b-94fb-eaa2c599a2bb
STIX ID: report--d970000f-9f26-567b-94fb-eaa2c599a2bb
Feed Name: The Hacker News
Raspberry Robin (aka QNAP worm), attributed to Storm-0856, has been observed actively incorporating one-day/zero-day exploits (e.g., CVE-2023-36802, CVE-2023-29360) for privilege escalation, improving anti-analysis/obfuscation, changing lateral movement to PAExec, and using randomized Tor onion addresses for C2; operators appear to obtain exploits from dark web sellers, enabling rapid use of newly disclosed vulnerabilities and sustaining large waves of attacks that facilitate additional payloads including ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
