<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Raspberry Robin, a new worm exploiting windows endpoints in Security for SMBs</title>
    <link>https://community.isc2.org/t5/Security-for-SMBs/Raspberry-Robin-a-new-worm-exploiting-windows-endpoints/m-p/51854#M11</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Raspberry Robin, a new worm exploiting windows endpoints is here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The report reads:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"Raspberry Robin is spreading to new Windows systems via infected USB drives containing a malicious .LNK file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Once the USB device is attached and the user clicks the link, the worm spawns a msiexec process using cmd.exe to launch a malicious file stored on the infected drive.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It infects new Windows devices, communicates with its command and control servers (C2), and executes malicious payloads using several legitimate Windows utilities:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. fodhelper (a trusted binary for managing features in Windows settings),&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. msiexec (command line Windows Installer component),&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. and odbcconf (a tool for configuring ODBC drivers)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link to the full report:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/amp/" target="_blank" rel="noopener"&gt;https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/amp/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 10:14:05 GMT</pubDate>
    <dc:creator>Ashwani_Paliwal</dc:creator>
    <dc:date>2023-10-09T10:14:05Z</dc:date>
    <item>
      <title>Raspberry Robin, a new worm exploiting windows endpoints</title>
      <link>https://community.isc2.org/t5/Security-for-SMBs/Raspberry-Robin-a-new-worm-exploiting-windows-endpoints/m-p/51854#M11</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Raspberry Robin, a new worm exploiting windows endpoints is here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The report reads:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"Raspberry Robin is spreading to new Windows systems via infected USB drives containing a malicious .LNK file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Once the USB device is attached and the user clicks the link, the worm spawns a msiexec process using cmd.exe to launch a malicious file stored on the infected drive.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It infects new Windows devices, communicates with its command and control servers (C2), and executes malicious payloads using several legitimate Windows utilities:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. fodhelper (a trusted binary for managing features in Windows settings),&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. msiexec (command line Windows Installer component),&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. and odbcconf (a tool for configuring ODBC drivers)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link to the full report:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/amp/" target="_blank" rel="noopener"&gt;https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/amp/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:14:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Security-for-SMBs/Raspberry-Robin-a-new-worm-exploiting-windows-endpoints/m-p/51854#M11</guid>
      <dc:creator>Ashwani_Paliwal</dc:creator>
      <dc:date>2023-10-09T10:14:05Z</dc:date>
    </item>
  </channel>
</rss>

