S1130: Raspberry Robin
Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.CitationTrendMicro RaspberryRobin 2022CitationRedCanary RaspberryRobin 2022CitationHP RaspberryRobin 2024 The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."CitationAvast RaspberryRobin 2022 The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.CitationMicrosoft RaspberryRobin 2022
Security context for executives and security teams
Raspberry Robin matters because it turns ordinary Windows endpoint use and removable media handling into an initial-access and follow-on payload risk. The ATT&CK entry describes malware that spreads through infected USB devices with malicious LNK objects and retrieves remote payloads, with documented use as a precursor to information stealers, ransomware-enabling tooling, and other malware families. For leaders, the decision point is whether endpoint, USB, script, command-line, and web egress controls can interrupt the chain early enough to avoid a larger incident.
Executive priority
Prioritize Raspberry Robin as an operational resilience and incident-readiness scenario for Windows environments, especially where removable media is permitted or difficult to eliminate. It is useful for testing whether policy, endpoint logging, network egress monitoring, and response playbooks can connect a user-executed USB/LNK event to later behaviors such as command execution, WMI use, LOLBin proxy execution, payload download, discovery, masquerading, cleanup, and web-based command-and-control. Because MITRE provides no official detection text for this object, executives should ask for evidence of telemetry coverage and practiced response decisions rather than assurance based only on signatures.
Technical view
Validate coverage around the behaviors linked to Raspberry Robin: removable media replication and user execution, Windows command shell and WMI execution, abuse of signed Windows utilities such as msiexec.exe, odbcconf.exe, and regsvr32.exe, obfuscation and packing, process hollowing, discovery commands, file deletion or persistence cleanup, web protocol C2, web services, and ingress tool transfer. Detection engineering should correlate USB insertion or LNK execution with unusual child processes, remote payload retrieval, DLL execution paths, suspicious LOLBin parameters, and short-lived artifacts that may be deleted. IR teams should preserve removable media evidence, endpoint process trees, file system artifacts, and network destinations before cleanup reduces forensic value.
Likely telemetry
- Windows endpoint process creation and command-line telemetry
- Removable media insertion and file execution events
- LNK file creation, modification, and execution evidence
- DLL load and module execution telemetry
- WMI activity logs and endpoint management events
Detection direction
- Build correlations from removable media or LNK execution to script/command execution and outbound web traffic rather than relying on a single indicator.
- Tune LOLBin detections for context: signed Windows utilities are common, so prioritize unusual parent-child relationships, remote content access, DLL execution, and execution from removable or user-writable paths.
- Monitor for discovery activity after initial execution, including user, process, system, and file/directory enumeration, as this may indicate staging for follow-on payloads.
- Account for evasion: packing, obfuscation, masqueraded file types, masqueraded services/tasks, process hollowing, and file deletion can reduce the value of static signatures and post-event file collection.
- Review visibility gaps where web protocols and legitimate web services are broadly allowed, because this can obscure command-and-control or payload transfer in normal traffic.
Mitigation priorities
- Reduce removable media risk first: restrict or control USB execution where business permits and ensure exceptions are documented and monitored.
- Harden Windows execution paths by limiting unnecessary script, command shell, WMI, and signed utility abuse through policy and application control where feasible.
- Improve egress control and monitoring for endpoints so remote payload retrieval and web-service-based communications are not treated as unmanaged background noise.
- Ensure endpoint protection and logging preserve process lineage, command lines, file events, and network context long enough for investigation.
- Prepare IR playbooks for USB/LNK-originated infection chains, including evidence collection from the host, removable device, and network logs before artifact cleanup occurs.
Additional notes and limits
The supplied ATT&CK object identifies Raspberry Robin as Windows initial-access malware active through early 2024 and notable for infected USB devices containing malicious LNK objects that retrieve remote hosted payloads. Relationship context expands the defensive focus to execution, stealth, discovery, command-and-control, ingress transfer, and removable media replication techniques. The object also notes that Raspberry Robin has been used as a precursor to other payloads, which makes early containment and evidence preservation more important than malware-family naming alone.
MITRE does not provide an official detection section for this object, and the supplied tactics field is not specified for the malware object itself. This take therefore uses the official description, external references list, platform field, and stated technique relationships only. Local conclusions about exposure, active intrusion, control effectiveness, or detection coverage require environment-specific telemetry and validation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Raspberry Robin
Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024. The malware is notable for spreading via infected USB devices containing a malicious LNK object that, on execution, retrieves remote hosted payloads for installation. Raspberry Robin has been widely used against various industries and geographies, and as a precursor to information stealer, ransomware, and other payloads such as SocGholish, Cobalt Strike, IcedID, and Bumblebee.CitationTrendMicro RaspberryRobin 2022CitationRedCanary RaspberryRobin 2022CitationHP RaspberryRobin 2024 The DLL componenet in the Raspberry Robin infection chain is also referred to as "Roshtyak."CitationAvast RaspberryRobin 2022 The name "Raspberry Robin" is used to refer to both the malware as well as the threat actor associated with its use, although the Raspberry Robin operators are also tracked as Storm-0856 by some vendors.CitationMicrosoft RaspberryRobin 2022
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
