Microsoft warns Raspberry Robin malware is getting a lot sourer
Date:
Mon, 31 Oct 2022 19:04:41 +0000
Description:
The mysterious malware is no longer dormant, as it starts delivering various ransomware, Microsoft reveals.
FULL STORY ======================================================================
The Raspberry Robin malware is being used to deliver all kinds of destructive code, including ransomware , to compromised endpoints , Microsoft has warned.
It seems the malware , first discovered late in 2021, and whose endgame was unknown at the time, transformed into an infection service available to
anyone with cash to pay.
Cybersecurity researchers from Microsoft have published a detailed blog post in which they describe Raspberry Robin as part of a complex and
interconnected malware ecosystem, with links to other malware families and alternate infection methods. Infection for hire
Whoever is behind Raspberry Robin kept busy over these last couple of weeks, as according to Microsoft Defender for Endpoint data, almost 3,000 devices in 1,000 organizations have experienced at least one Raspberry Robin payload-related alert in the last 30 days.
Payloads differ, the company further explained, from FakeUpdates malware
which led to possible EvilCorp activity, to IceID, Bumblebee, and Truebot. This is all July 2022.
In October 2022, though, Microsoft also spotted Raspberry Robin being used by FIN11 (AKA TA505, - the group behind the Dridex banking trojan and Locky ransomware). This activity led to Cobalt Strike hands-on-keyboard
compromises, the company explained, sometimes with a Truebot infection in between the Raspberry Robin and Cobalt Strike stages. Following the Cobalt Strike beacon, the group deployed the Clop ransomware.
All things considered, Microsoft concluded that the group behind Raspberry Robin is taking payments to deploy various malware and ransomware to its victims endpoints. Read more
Nasty Windows worm spreads to hundreds of networks via infected USB drives
This dangerous new malware is attacking Windows devices via infected USB
drives
These are the best internet security suites out there
Given the interconnected nature of the cybercriminal economy, its possible that the actors behind these Raspberry Robin-related malware campaignsusually distributed through other means like malicious ads or emailare paying the Raspberry Robin operators for malware installs, the report concludes.
Raspberry Robin was first identified when researchers from Red Canary discovered a cluster of malicious activity. The malware is usually
distributed offline, via infected USB drives. After analyzing an infected thumb drive, the researchers discovered that the worm spreads to new devices via a malicious .LNK file. Keep track of traffic with the best firewalls out there
======================================================================
Link to news story:
https://www.techradar.com/news/microsoft-warns-raspberry-robin-malware-is-gett ing-a-lot-sourer/
--- Mystic BBS v1.12 A47 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)