Exposed: 200 Hidden Command Centers Fueling Raspberry Robin’s Criminal Access Network


# Raspberry Robin Malware: Extensive C2 Network Uncovered

A recent investigation has identified nearly 200 unique command-and-control (C2) domains linked to Raspberry Robin malware. Security firm Silent Push describes this threat as “a complex and evolving threat actor providing initial access broker services to numerous criminal groups, many with connections to Russia.”

Since its first appearance in 2019, Raspberry Robin has served as a delivery mechanism for various malicious payloads including SocGholish, Dridex, LockBit, IcedID, BumbleBee, and TrueBot. The malware, also known as a QNAP worm, typically leverages compromised QNAP devices to distribute its payload.

## Evolution of Attack Methods

Raspberry Robin’s attack strategies have evolved to include:
– Distribution via Discord through archives and Windows Script Files
– Acquisition of one-day exploits for local privilege escalation
– Operation as a pay-per-install botnet for delivering secondary malware
– USB-based propagation using compromised drives with disguised Windows shortcut files

The U.S. government has indicated that Russian threat actor Cadet Blizzard may have utilized Raspberry Robin for initial access to targets.

## Infrastructure Analysis

Silent Push and Team Cymru’s investigation revealed:
– A single IP address functioning as a data relay connecting all compromised QNAP devices
– Communication through Tor relays, likely for command issuance
– Over 180 unique C2 domains with distinctive characteristics:
– Short domain names (e.g., q2.rs, m0.wf)
– Fast flux techniques to evade takedown attempts
– Common TLDs including .wf, .pm, .re, .nz, .eu, .gy, .tw, and .cx
– Registration through niche registrars
– Name servers predominantly hosted by Bulgarian company ClouDNS

The malware’s association with Russian government threat actors aligns with its history of collaboration with numerous threat groups connected to Russia, including LockBit, Dridex, SocGholish, and Evil Corp.

Share This Article