Microsoft says it has detected a Windows worm called Raspberry Robin on the networks hundreds of organizations. of The malware spreads via infected USB devices and was first detected in September 2021 by analysts at Red Canary .
Cybersecurity firm Sekoia observed malware using QNAP NAS devices as command and control (C2) servers in early November [PDF].

Microsoft's findings align with those of researchers at Red Canary, which also detected this Windows worm on the networks of several customers (some in the technology and construction sectors).
See also: Microsoft Defender: Detecting vulnerabilities in Android/iOS devices on corporate networks
Although Microsoft has observed the malware connecting to addresses on the Tor, threat actors have yet to exploit the access they gained to their victims' networks, despite the fact that they could easily escalate their attacks. Raspberry Robin can bypass User Account Control (UAC) on infected systems using legitimate Windows tools.
Raspberry Robin abuses legitimate Windows tools
As mentioned above, the Raspberry Robin worm spreads to new Windows systems via infected USB drives. These devices contain a malicious .LNK file.
Once the USB device is connected and the user clicks on the link, the worm creates an msiexec process using cmd. exe to launch a malicious file stored on the infected drive.
See also: Google updates Chrome password manager
Thus, it infects new Windows devices, communicates with command and control servers (C2), and executes malicious payloads using various legitimate Windows utilities:
- fodhelper (a reliable binary for managing features in Windows settings),
- msiexec (command line Windows Installer component),
- and odbcconf (a tool for configuring ODBC drivers).

“While msiexec.exe downloads and executes legitimate installer packages, cybercriminals also use it to deliver malware,” explained Red Canary researchers.
See also: Hackers breach verified Twitter accounts and steal credentials
Security researchers who discovered the Raspberry Robin Windows worm have yet to attribute the malware to a specific threat group and are still trying to discover the ultimate goal of its operators.
However, Microsoft has flagged this campaign as high-risk , given that the attackers have the ability to download and deploy additional malware on victims ' networks , while also being able to escalate their privileges at any time.
Source: www.bleepingcomputer.com
