Hackers are constantly changing their tactics to avoid detection and now it appears they have resurrected a windows worm to infect vulnerable PCs with other malware strains and even Data ransom.
Identified in 2021, Raspberry Robin was first used by hackers to attack technology and manufacturing companies. However, instead of spreading this malware online, they used usb flash drives that were sent to specific organizations. While you should never connect a random USB flash drive to your computer, some employees did so unknowingly, causing their entire company network to become infected.
Now, according to a new report of HP Wolf Security, Raspberry Robin is back in action, but this time hackers are using a little-known Windows file type to distribute it. If you are using one of the best Windows laptops or even a PC you built yourself, here’s everything you need to know about this nasty Windows worm, along with some steps on how to keep you and your computer safe.
From USB flash drives to Windows script files
Instead of using USB flash drives, hackers are now using Windows Script Files (WSF) to distribute Raspberry Robin in this new campaign.
For those unfamiliar, these scripts are often used by IT administrators and legitimate software to automate tasks within Windows. However, like most tools, they can be abused by hackers and other cybercriminals in their attacks.
In this latest campaign, the hackers responsible are distributing these malicious files using several different domains and subdomains. However, according to Hacker News, it’s not entirely clear how they direct potential victims to these particular sites. However, HP Wolf Security researchers believe that spam emails either malvertising It could be how hackers are doing it.
These WSF files are highly obfuscated, making it more difficult for the best antivirus software and other security tools to identify that they are truly dangerous. In fact, the malware tracking site VirusTotal has not yet classified them as malicious.
What makes Raspberry Robin so dangerous is that this malware is frequently used to remove other malware strains such as SocGholish, Cobalt Strike, ice cream ID, BumbleBee and Truebot on infected PCs. Think of it as a precursor to a more serious malware infection that can steal passwords, along with other financial and sensitive data from your computer. Likewise, Raspberry Robin can also be used to infect your computer and others on the same network with ransomware.
How to keep your PC protected from malware

Just like with your smartphone, you need to be very careful when downloading new files online when using your PC. As a general rule, it’s best to stick to well-known brands and websites when it comes to downloading anything.
As Raspberry Robin could spread through spam emails, you should avoid clicking on any links or downloading any attachments that may contain an email from an unknown sender. Even then, hackers could compromise the email account of someone you know to use their email address in future attacks. That’s why it’s best to avoid downloading anything from an email unless you have antivirus software installed.
Fortunately, Windows computers come preinstalled with Windows Defender and this built-in antivirus has become much better at defending against malware infections and other attacks in recent years. Still, it might be worth upgrading to paid antivirus software or even sign for the the best protection against identity theft if you want to be safer.
To make their attacks successful, hackers always find new ways to avoid detection. This is why you should be careful online and think twice before downloading anything.
- This Android Banking Trojan Now Lets Hackers Control Your Phone Remotely
- LG TVs are at risk of hackers spying on users: what to do now
- Macs threatened by malware that steals information and spreads through ads and fake software