Raspberry Robin, also tracked by Microsoft as Storm-0856 and also known as Roshtyak, is a highly evasive malware operation centered on a worm that evolved into a major malware distribution platform and likely initial access broker. Activity linked to the operation dates back to at least 2019. The operators remain unidentified. Raspberry Robin is best known for initial compromise via infected removable media, especially malicious shortcut files on external drives, and has also been delivered through archive attachments distributed via Discord. In observed campaigns, the malware has abused legitimate Windows utilities such as cmd.exe and msiexec.exe, and has used DLL sideloading, heavy obfuscation, mixed-case command execution, sandbox evasion, and rapidly adopted local privilege escalation exploits. It has also changed communication methods and lateral movement techniques over time to reduce the effectiveness of signature-based detection. The operation appears to function as an access-enablement and payload-delivery service for other criminal activity. Raspberry Robin access has been associated with follow-on delivery involving FakeUpdates, Fauppod, IcedID, TrueBot, BumbleBee, FIN11, and Clop-linked activity, and has also been connected with activity overlapping Evil Corp tradecraft. Observed post-compromise behavior has included payload delivery, persistence, privilege escalation, lateral movement, and exfiltration of device information and credentials. Raspberry Robin has targeted a broad range of sectors, including public administration, finance, manufacturing, retail, education, and transportation. Its infrastructure has included compromised IoT devices and backup use of Tor exit nodes. Overall, Raspberry Robin is notable for combining worm-like propagation, stealthy execution through trusted system binaries, and access-broker behavior that enables downstream financially motivated malware and extortion ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker activity cluster associated with Raspberry Robin infrastructure, providing access to other criminal groups (noted as many having Russia connections).
A highly evasive worm malware operation assessed as functioning as an initial access broker and malware distribution platform, using infected USB drives, malicious LNK files, msiexec-based C2 retrieval, IoT-backed C2 infrastructure, TOR backup infrastructure, and privilege-escalation exploits to spread and deliver follow-on payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.