HomeSecurityRaspberry Robin malware evolves with one-day exploits

Raspberry Robin malware evolves with one-day exploits

Recent versions of the Raspberry Robin malware are more sophisticated and implement one-day exploits, which are only applied to systems that are vulnerable to them.

See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

Raspberry Robin malware

According to a report by Check Point, the Raspberry Robin recently used at least two one-day exploits, which suggests that the malware carrier either has the ability to develop the code or has sources that provide it.

Raspberry Robin is an add-on first detected by Red Canary, a detection and response management company, in 2021. It spreads primarily via removable storage media, such as USB , and creates an initial access to infected systems to facilitate the installation of additional payloads.

It has been linked to malicious actors such as EvilCorp, FIN11, TA505, Clop ransomware , and other malicious enterprises, but its creators and maintainers remain unknown.

Since its discovery, the Raspberry Robin malware has been continuously evolving, adding new features, evasion techniques, and adopting various distribution methods. One example of the evasion technique it adopted was dropping fake deliveries to mislead researchers.

Check Point reports that it has seen an increase in Raspberry Robin attacks since October 2023, with large waves of attacks targeting systems around the world. One change in recent campaigns is the use of the Discord to drop malicious files on the target, possibly after sending the links via email.

The files include a signed executable (OleView.exe) and a malicious DLL file (aclui.dll) that is loaded in parallel when the victim runs the executable, activating the Raspberry Robin malware on the system.

When Raspberry Robin is first run on a computer, it will automatically attempt to elevate privileges on the device using a variety of one-day exploits.

Check Point notes that the new Raspberry Robin campaign exploits CVE-2023-36802 and CVE-2023-29360, two elevation of privilege vulnerabilities in Microsoft Streaming Proxy services and the Windows TPM device driver. In both cases, according to the researchers, Raspberry Robin began exploiting the flaws using a previously unknown exploit, just a month after the security issues were published on June 13 and September 12, 2023.

CVE-2023-36802, which allows attackers to escalate their privileges to SYSTEM level, Cyfirma reported that an exploit was available for purchase on the Dark Web as of February 2023, seven months before Microsoft recognized and addressed the issue.

This timeline suggests that the Raspberry Robin malware acquires one-day exploits from external sources almost immediately after their publication, as the cost of zero-days is likely prohibitive even for larger criminal operations.

See also: New Python variant of Chaes Malware targets banking and logistics industries

In its report, Check Point also highlights several advanced developments in the latest versions of Raspberry Robin, including new anti-analysis, evasion, and lateral movement mechanisms.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

one-day exploits

To evade security tools and operating system defenses, the malware now attempts to terminate specific processes such as 'runlegacycplelevated.exe', which are related to User Account Control (UAC), and interferes with the NtTraceEvent API to avoid detection by Event Tracing for Windows (ETW).

Additionally, Raspberry Robin now checks whether specific APIs, such as 'GetUserDefaultLangID' and 'GetModuleHandleW', are specified by the first word of the API function to detect any monitoring processes from security products.

Another interesting new tactic is the use of a routine that uses the “AbortSystemShutdownW” and “ShutdownBlockReasonCreate” APIs to prevent system shutdowns that could interrupt malware activity.

To hide the command and control (C2) addresses, the malware first randomly communicates with one of 60 predefined Tor domains that point to well-known websites, in order to make the initial communications appear innocent.

Finally, the Raspberry Robin malware now uses PAExec.exe instead of PsExec.exe to download its payload directly from the hosting site. This decision was likely made to increase its stealth presence, as PsExec.exe is known to be exploited by hackers.

Researchers believe that Raspberry Robin will continue to evolve and add new exploits to its arsenal, searching for code that has not yet been published. Based on observations during the malware analysis, it is likely that the perpetrators of the malware are not affiliated with a developer providing the exploit code.

Check Point's report provides a list of indicators of compromise for the Raspberry Robin, which includes hashes for the malware, multiple domains on the Tor network, and Discord URLs for downloading the malicious file.

See also: Payment applications are at risk from Malware attacks!

What is the meaning of one-day exploits?

One-day exploits refer to vulnerabilities that are discovered and exploited within a single day. This means that attackers exploit these vulnerabilities before software manufacturers have a chance to create and distribute patches.

This is extremely dangerous for digital assets, as these types of attacks can cause significant damage before there is a chance to react. One-day exploits are also difficult to detect, as they are designed to exploit vulnerabilities that are not yet known to the general public.

To protect against one-day exploits, it is important to keep systems up to date and use security tools that can detect and block threats before they cause damage. Also, training staff on security can help prevent these types of attacks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS