"Raspberry Robin Malware Spreading Through WSF Files: How to Stay Safe"

1 min read
Source: The Hacker News
"Raspberry Robin Malware Spreading Through WSF Files: How to Stay Safe"
Photo: The Hacker News
TL;DR Summary

A new wave of the Raspberry Robin malware campaign has been discovered, spreading through malicious Windows Script Files (WSFs) since March 2024. The malware, also known as QNAP worm, has evolved into a downloader for various other payloads and is linked to the broader cybercrime ecosystem. The latest distribution vector involves the use of heavily obfuscated WSF files offered for download via various domains and subdomains, with the malware employing anti-analysis and anti-virtual machine techniques to evade detection. Additionally, it configures Microsoft Defender Antivirus exclusion rules to avoid being scanned, posing a serious infection risk.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

77%

41795 words

Want the full story? Read the original article

Read on The Hacker News