Ransomware
Raspberry Robin
Ransomware
Needs review
7 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog
because it self-identifies as ransomware-type malware, but no one
has curated a full summary or double-checked its reference links. Treat the details below as a starting point,
not a verified profile.
Also known as: Raspberry Robin
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1130) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- Raspberry Robin, Software S1130 — MITRE ATT&CK
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| sigma | Potential Raspberry Robin Aclui Dll SideLoading | test | 2024-07-31 |
| sigma | Potential Raspberry Robin Registry Set Internet Settings ZoneMap | test | 2024-07-31 |
| sigma | Potential Raspberry Robin CPL Execution Activity | test | 2024-03-07 |
| sigma | Rundll32 Spawned Via Explorer.EXE | test | 2023-08-31 |
| sigma | Potential Raspberry Robin Dot Ending File | test | 2023-02-05 |
| sigma | Raspberry Robin Initial Execution From External Drive | test | 2022-05-06 |
| sigma | Raspberry Robin Subsequent Execution of Commands | test | 2022-05-06 |