Cyber Security News

Raspberry Robin Malware Attacking Windows Systems With New Exploit for CLFS Driver Vulnerability

The cybersecurity landscape faces a persistent threat as Raspberry Robin, a sophisticated malware downloader also known as Roshtyak, continues its campaign against Windows systems with enhanced capabilities and evasion techniques.

First identified in 2021, this USB-propagated malware has demonstrated remarkable resilience and adaptability, primarily targeting enterprise environments through infected removable storage devices.

Raspberry Robin’s infection vector remains consistent with its original deployment strategy, leveraging compromised USB devices to infiltrate target networks.

Once executed, the malware establishes persistence and attempts to communicate with command-and-control infrastructure through TOR networks.

Raspberry Robin’s new obfuscated stack pointers (Source – Zscaler)

The malware’s operators have consistently refined their approach, implementing sophisticated obfuscation methods that challenge traditional detection mechanisms and complicate reverse engineering efforts.

Zscaler researchers identified significant evolutionary changes in Raspberry Robin’s architecture, particularly noting the integration of CVE-2024-38196, a local privilege escalation exploit targeting the Common Log File System driver vulnerability.

Raspberry Robin’s obfuscation for conditional statements (Source – Zscaler)

This critical addition enables the malware to elevate its privileges on compromised systems, potentially granting administrator-level access for deeper system infiltration.

The malware’s communication infrastructure has undergone substantial modifications, transitioning from AES-CTR encryption to the more robust ChaCha-20 algorithm for network data protection.

Raspberry Robin C2 dynamic correction algorithm (Source – Zscaler)

This encryption change, combined with randomly generated counter and nonce values per request, significantly enhances the malware’s ability to evade network-based detection systems.

Advanced Obfuscation and Persistence Mechanisms

The latest Raspberry Robin variants incorporate sophisticated obfuscation techniques designed to frustrate analysis efforts.

The malware now implements multiple initialization loops within functions featuring flattened control flow, effectively neutralizing brute-force decryption attempts that were previously successful against earlier versions.

struct encryptionInfo
{
    uint32_t nonce_part2;
    uint32_t nonce_part3;
    uint32_t counter;
    uint32_t nonce_part1;
};

Additionally, the malware employs obfuscated stack pointers and conditional statements, disrupting standard decompilation processes and requiring manual intervention from security analysts for proper analysis.

Integrate ANY.RUN TI Lookup with your SIEM or SOAR To Analyses Advanced Threats -> Try 50 Free Trial Searches

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

17 seconds ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

6 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

17 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago