Microsoft warns of USB worm

VG word pixels

Malware spreads on Windows networks

Windows users currently have to be wary of a network worm. Microsoft warns of the “Raspberry Robin” malware, which mainly spreads via USB.

news

Petya version 2.0 Green Petya
“Raspberry Robin” has been on the road since 2021.
© Malwarebytes Blog

Windows company networks currently have to beware of the “Raspberry Robin” malware. As “Bleeding computer” reported, Microsoft discovered the computer worm in the networks of several hundred organizations. “Raspberry Robin” is not a new acquaintance. The worm was already discovered in September 2021 by Red Canary security researchers discovered, which see a distribution especially in the technology and production sector:

“So far we’ve observed Raspberry Robin in companies with ties to the technology and manufacturing industries, although it’s not yet clear if there are other ties among the victims.”

Apparently, the malware is mainly spread via USB devices. This is where the descriptions from Microsoft and Red Canary match. The USB devices contain a malicious .lnk file that runs an msiexec.exe after activating the device. This then installs the malware on the system. “Raspberry Robin” then communicates with the network’s command and control servers (C2) and spreads independently via legitimate Windows services (fodhelper, msiexec and odbcconf).

Although Microsoft has currently been able to track down the worm in several organizations, the malware infection has not yet been actively exploited. The assignment to a specific hacker group is still pending. Nevertheless, Microsoft assumes that “Raspberry Robin” poses a high risk, since the infection can cause new malware to be installed at any time and unauthorized access to the network to take place.

Microsoft is currently informing users of Defender for Endpoint about the threat.

See also  PS Plus in July 2022: If you have Extra or Premium, you get a game directly with the release

4.7.2022 from
Alan Friedrichs

Continue to home page

more on the subject

Microsoft: November Patch Day

Microsoft Patch Day

Fixed critical vulnerabilities in Windows 8 and RT

Microsoft closed a total of 19 security gaps with its Tuesday update. These include vulnerabilities classified as critical in all…

10 Windows Calculator Pro Tips

According to Microsoft

Windows 10: Why tuning and tidying tools tend to hurt…

Microsoft explains why Windows 10 classifies some seemingly useful tuning and cleaning tools as potentially harmful and removes them.

WannaCry ransomware

Blackmail Trojan

WannaCry: First decryption tools, almost only Windows 7…

WannaCry victims are given initial decryption tools, but the chances of success are slim. It turns out that Windows 7 is primarily…

updates

security

Windows Defender: Patch against vulnerability creates new…

Google found a vulnerability in the Windows Malware Protection Engine. It came with an older Microsoft patch that closed another leak…

What is the current Windows 10 version?

Version history and comparison

Windows 10: Current version and updates at a glance

What is the current Windows 10 version? Which version do I have installed? Here are the answers and an overview of the current versions.

Reference-www.pc-magazin.de