logo

Raspberry Robin Returns: New Malware Campaign Spreading Through WSF Files

ID: ee509bd7-2cd2-5501-9979-1db7772c91f4

STIX ID: report--ee509bd7-2cd2-5501-9979-1db7772c91f4

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-04-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers identified a March 2024 wave of the Raspberry Robin campaign distributing via heavily obfuscated Windows Script Files (WSFs) that perform anti-analysis and anti-VM checks, enforce a minimum Windows build, detect/avoid AV processes, add Microsoft Defender exclusions, and use curl to retrieve a main DLL payload; Raspberry Robin acts as a downloader for payloads such as SocGholish, Cobalt Strike, IcedID, BumbleBee, and TrueBot and is tied to the Storm-0856 cybercrime cluster.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.