HomeSecurityMicrosoft links Raspberry Robin malware to Evil Corp attacks

Microsoft links Raspberry Robin malware to Evil Corp attacks

Microsoft discovered that an access broker tracked as DEV-0206 is using the Windows worm Raspberry Robin to deploy a malware downloader on networks where it also found evidence of malicious activity that matches Evil Corp's tactics.

See also: The US federal judicial system was hit by a sophisticated cyberattack

Raspberry Robin

"On July 26, 2022, Microsoft researchers discovered that the FakeUpdates malware is being delivered via existing Raspberry Robin infections," Microsoft revealed on Thursday.

"FakeUpdates activity associated with DEV-0206 on affected systems has since led to subsequent actions that resemble the behavior of DEV-0243 prior to the ransomware."

See also: Ransomware: Ransoms are falling as fewer victims choose to pay

According to a threat intelligence advisory shared with enterprise customers, Microsoft has detected the Raspberry Robin malware on the networks of hundreds of organizations from a wide range of industry sectors.

Microsoft links Raspberry Robin malware to Evil Corp attacks

The malware, first detected in September 2021 by Red Canary intelligence analysts, spreads via infected USB to other devices on a target's network after being deployed on a compromised system.

Microsoft's findings match those of Red Canary's Detection Engineering team, which also detected it on customer networks in the technology and manufacturing sectors .

This is the first time that security researchers have found evidence of how the threat actors behind Raspberry Robin plan to exploit the access they gained to their victims ' networks using this worm.

Evil Corp, ransomware and sanctions evasion

Evil Corp, the cybercrime group that appears to be exploiting Raspberry Robin's access to corporate networks (tracked by Microsoft as DEV-0243), has been active since 2007 and is known for promoting the Dridex malware and moving into ransomware development.

From Locky ransomware and its own ransomware strain BitPaymer, the group moved to deploy the new WastedLocker ransomware starting in June 2019.

Since March 2021, Evil Corp has moved on to other strains known as Hades ransomware, Macaw Locker, and Phoenix CryptoLocker, and was eventually observed by Mandiant developing ransomware as a LockBit affiliate since mid-2022.

See also: Google and Apple under investigation for scam crypto apps in app stores

Switching between ransomware payloads and adopting a Ransomware as a Service (RaaS) affiliate role are part of Evil Corp's efforts to evade sanctions imposed by the Treasury Department for using Dridex to cause in financial losses .

Raspberry Robin Evil Corp

After being sanctioned by the US government in 2019, ransomware trading firms refused to facilitate ransom payments for organizations affected by Evil Corp ransomware attacks to avoid legal action or fines from the US Treasury Department .

Using malware from other groups allows Evil Corp to distance itself from well-known tools that allow their victims to pay ransoms without facing risks associated with violating OFAC regulations.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS