HomeSecurityMicrosoft: "Raspberry Robin" Windows worm detected on hundreds of networks

Microsoft: “Raspberry Robin” Windows worm detected on hundreds of networks

Microsoft says it has detected a Windows worm called Raspberry Robin on the networks hundreds of organizations. of The malware spreads via infected USB devices and was first detected in September 2021 by analysts at Red Canary .

Cybersecurity firm Sekoia observed malware using QNAP NAS devices as command and control (C2) servers in early November [PDF].

Raspberry Robin

Microsoft's findings align with those of researchers at Red Canary, which also detected this Windows worm on the networks of several customers (some in the technology and construction sectors).

See also: Microsoft Defender: Detecting vulnerabilities in Android/iOS devices on corporate networks

Although Microsoft has observed the malware connecting to addresses on the Tor, threat actors have yet to exploit the access they gained to their victims' networks, despite the fact that they could easily escalate their attacks. Raspberry Robin can bypass User Account Control (UAC) on infected systems using legitimate Windows tools.

Raspberry Robin abuses legitimate Windows tools

As mentioned above, the Raspberry Robin worm spreads to new Windows systems via infected USB drives. These devices contain a malicious .LNK file.

Once the USB device is connected and the user clicks on the link, the worm creates an msiexec process using cmd. exe to launch a malicious file stored on the infected drive.

See also: Google updates Chrome password manager

Thus, it infects new Windows devices, communicates with command and control servers (C2), and executes malicious payloads using various legitimate Windows utilities:

  • fodhelper (a reliable binary for managing features in Windows settings),
  • msiexec (command line Windows Installer component),
  • and odbcconf (a tool for configuring ODBC drivers).
Windows worm

“While msiexec.exe downloads and executes legitimate installer packages, cybercriminals also use it to deliver malware,” explained Red Canary researchers.

See also: Hackers breach verified Twitter accounts and steal credentials

Security researchers who discovered the Raspberry Robin Windows worm have yet to attribute the malware to a specific threat group and are still trying to discover the ultimate goal of its operators.

However, Microsoft has flagged this campaign as high-risk , given that the attackers have the ability to download and deploy additional malware on victims ' networks , while also being able to escalate their privileges at any time.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS