March 25, 2024, 10:20 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Fast facts




  1. Raspberry Robin, previously disseminated through USB drives, now employs Discord for distribution.




  2. The utilization of Raspberry Robin has been observed dropping a variety of payloads, including ransomware and stealers, such as CLOP.




  3. Tools like RunDLL32 and Shell32.dll are abused for living off the land for proxy execution of malicious CPL files




  4. Raspberry Robin, also known as the QNAP worm, is attributed to a threat actor dubbed DEV-0856.




Swachchhanda Shrawan Poudel

Security Research

Download report

Share This Story

In …

clop cpl discord distribution dll drives facts fast living off the land love malicious payloads proxy ransomware raspberry raspberry robin robin rundll32 stealers tools usb usb drives

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Salesforce Solution Consultant

@ BeyondTrust | Remote United States

Divisional Deputy City Solicitor, Public Safety Compliance Counsel - Compliance and Legislation Unit

@ City of Philadelphia | Philadelphia, PA, United States

Security Engineer, IT IAM, EIS

@ Micron Technology | Hyderabad - Skyview, India

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

Werkstudent Cybersecurity (m/w/d)

@ Brose Group | Bamberg, DE, 96052