HomeSecurityRaspberry Robin returns and spreads via WSF files

Raspberry Robin returns and spreads via WSF files

Cybersecurity researchers have discovered a new Raspberry Robin campaign, which has been spreading malware via Windows Script Files (WSF) since March 2024.

See also: Raspberry Robin malware evolves with one-day exploits

Raspberry Robin WSF

Raspberry Robin, also called the QNAP worm, was first detected in September 2021 and has since evolved into a downloader for various other payloads in recent years, including SocGholish, Cobalt Strike, IcedID, BumbleBee , and TrueBot, and also serves as a precursor for ransomware.

While the malware was initially distributed via USB devices containing LNK files that retrieved the payload from a compromised QNAP device, it has since adopted other methods, such as social engineering and malvertising.

It is attributed to an emerging threat cluster tracked by Microsoft as Storm-0856, which has links to the broader cybercrime ecosystem that includes groups like Evil Corp, Silence, and TA505.

The latest distribution vector of the Raspberry Robininvolves the use of WSF files offered for download through various domains and subdomains.

See also: Raspberry Robin malware becomes more powerful

It is currently unclear how attackers direct victims to these URLs, although it is suspected that it could be either through spam or malicious advertising campaigns.

Raspberry Robin returns and spreads via WSF files

The very obscure WSF file acts as a downloader to retrieve the main DLL payload from a remote server, using the curl command, but not before a series of anti-analysis and anti-virtual machine evaluations, to determine if it is running in a virtual environment.

It is also designed to terminate execution if the Windows operating system version number is less than 17063 (which was released in December 2017) and if the list of running processes includes antivirus processes related to Avast, Avira, Bitdefender, Check Point, ESET, and Kaspersky.

Additionally, it configures Microsoft Defender Antivirus exclusion rules in an attempt to bypass detection by adding the entire primary drive to the exclusion list and preventing it from being scanned.

See also: Beware! Bumblebee malware has reappeared!

What are the methods of protection against malware?

The first and most important method of protection against malware, such as Raspberry Robin that spreads via WSF files, is to use reliable security software. This software should include antivirus, anti-malware, and anti-spyware features. In addition, it is important to keep your operating system and all applications up to date. These updates often include security patches that can protect your computer from the latest threats. You should also be careful with emails and messages you receive. Many malware are spread through seemingly harmless links or attachments. Using strong passwords and changing them regularly is another important method of protection.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS