Wednesday June 25, 2025
Advertisement
Edit
The Current Bite The Current Bite
  • most recent news
  • trending news
  • most read
  • All Video
  • Image gallery
  • more
Technology

Introducing Windows 11

August 21, 2021
Technology

Launching Mi 5X Series

August 26, 2021
Mobile

Infinix Hot 11S India

August 27, 2021
News

Xiaomi to invest $10bn

September 1, 2021
News

FBI Alerts About Hive

September 1, 2021
Mobile

OnePlus Buds Pro Matte

September 2, 2021
  • Accessibility
  • Help
  • Contact
  • About qoxag
The Current Bite The Current Bite

Breaking News

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh Khan on King;

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

Border 2 Gets Even Stronger! Diljit Dosanjh Joins the Squad

Fans Demand Mr. India 2 After Viral BTS Pic

Rajkummar Rao Shares Unseen BTS Pic from Stree 2: “Deleted

AMMA Leadership Resigns Amid Sexual Misconduct Allegations

“Stree 2 Success Party: New Photos of Shraddha Kapoor, Kriti

“Explained: The Arshad Warsi-Prabhas Controversy—’Joker’ Comment and Reactions from Nani

“‘Stree 2’ Global Box Office Update on Day 7: Shraddha

IC 814: The Kandahar Hijack | Official Trailer | Vijay

The Current Bite The Current Bite
  • Home
  • News
  • Technology
  • Entertainment
  • Sports
  • Gadgets
  • Finance
  • TCB-How to
  1. Home
  2. News
  3. New ‘Raspberry Robin’ Malware Spreading via External Drives
 New ‘Raspberry Robin’ Malware Spreading via External Drives
News Technology

New ‘Raspberry Robin’ Malware Spreading via External Drives

by VICKY May 6, 2022 0 Comment

In attribution of the malware to a group dubbed “Raspberry Robin,” Red Canary researchers discovered that the malware “leverages Windows Installer to reach out to QNAP-associated domains and download a malicious DLL.”
The first indications of the phenomenon are believed to date to September 2021. The first signs of the disease were found in companies with connections to the manufacturing and technology sectors.

Attack chains that are associated with Raspberry Robin start with connecting an infected USB drive to the Windows machine. The device contains the payload of the worm, which is an .LNK shortcut file that is attached to the legitimate folder.
The worm takes care of spawning a fresh process by using cmd.exe to open and run the malicious file that is stored within the hard drive.


Then, it launches explorer.exe and msiexec.exe which is the latter is used to enable external network communications to an unauthenticated domain for command-and-control (C2) purposes as well as in order to install and download an DLL library.
The dangerous DLL is loaded and executed by a series of legitimate Windows tools like fodhelper.exe, rundll32.exe to rundll32.exe and odbcconf.exe which effectively bypasses User Account Control (UAC).

Another feature common to Raspberry Robin detections is the presence of outbound C2 contact between three processes: regsvr32.exe, rundll32.exe, and dllhost.exe to IP addresses that are associated to Tor nodes.
However, the goals of the operators aren’t clear at the moment. It’s not clear how or exactly where external drives are affected It’s believed that the infection is carried out offline.

“We also don’t know why Raspberry Robin installs a malicious DLL,” the researchers claimed. “One hypothesis is that it may be an attempt to establish persistence on an infected system.”

Share This:

  • 0
    Facebook
Tags: #informationtechnology #latestvirus #malware #microsoft #RaspberryRobin #RaspberryRobinmalware
Previous post
Next post

VICKY

administrator

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Entertainment
  • Finance
  • Gaming
  • Mobile
  • Movies Trailers
  • News
  • Sports
  • TCB-How to
  • Technology
  • Uncategorized
Most Recent
Entertainment

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh

May 16, 2025
Entertainment

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

September 6, 2024
Entertainment

Border 2 Gets Even Stronger! Diljit Dosanjh

September 6, 2024
Entertainment

Fans Demand Mr. India 2 After Viral

August 28, 2024
Social Profile

Daily Newsletter

Get all the top stories from Qoxag to keep track.

RELATED Stories for you
News Technology

Dangerous new malware dances past more than

by VICKY July 9, 2022

Specialists have found a new malware test fit for stowing away from more than

News Technology

Microsoft to suspend all new sales of

by VICKY March 7, 2022

Microsoft President Brad Smith says it will take additional steps as this situation continues

News Technology

Tech Update: Microsoft’s $16-Billion Bid for Nuance

by VICKY December 22, 2021

The European Commission on Tuesday granted Microsoft unconditional antitrust approval for its $16 billion (roughly

Copyright © 2025 Teqtive Solutions. All Right Reserved.