No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Raspberry Robin Jumps on 1-Day Bugs to Nest Deep in Windows Networks

February 13, 2024
in Protection
0
Raspberry Robin Jumps on 1-Day Bugs to Nest Deep in Windows Networks


The Raspberry Robin worm is incorporating one-day exploits almost as soon as they’re developed, in order to improve on its privilege escalation capabilities. 

Researchers from Check Point suspect that the developers behind the initial access tool are contracting with Dark Web exploit traffickers, allowing them to quickly incorporate new exploits for obtaining system-level privileges before such exploits are disclosed to the public, and before many affected organizations have gotten around to patching their associated vulnerabilities.

“It’s a very powerful piece of the program that gives the attacker much more ability in terms of evasion, and performing higher-privileged actions than they could in any other scenario,” explains Eli Smadja, group manager for Check Point.

Raspberry Robin: Incorporating Exploits Faster Now

Raspberry Robin was first discovered in 2021, and outed in a Red Canary blog post the following year. In the time since, its developers have become much more proactive, upgrading their tool in a fraction of the time they used to take.

Consider, for example, an early upgrade: when it incorporated an exploit for CVE-2021-1732, a privilege escalation vulnerability with a “high” 7.8 out of 10 score on the CVSS scale. The Win32k Windows driver bug was first disclosed in February of 2021, but it was only integrated into Raspberry Robin the following year.

Contrast that with another privilege escalation vulnerability from this past June: CVE-2023-29360, a “high” 8.4 out of 10 bug in Microsoft Stream’s streaming service proxy. Raspberry Robin was already exploiting it by August, while a public exploit wouldn’t come to light until the following month.

Then there was CVE-2023-36802, a similar bug in Microsoft Stream with a 7.8 CVSS rating. First disclosed on September 12, it was being exploited by Raspberry Robin by early October, again before any public exploit was released (the developers don’t deserve too much credit in this case, as an exploit had been available on the Dark Web since February.)

In other words, the progression of the time the group takes to weaponize vulnerabilities after disclosure has gone from one year, to two months, to two weeks.

To explain their quick work, Check Point suggests that the worm developers are either purchasing their exploits from one-day developers on the Dark Web, or developing them themselves. Certain misalignments between the worm and exploit codes suggest that the former scenario is more likely.

A Widespread, Effective Initial Access Cyber Threat

In only its first year active, Raspberry Robin was already one of the world’s most popular worms, with thousands of infections per month. Red Canary tracked it as the seventh most prevalent threat of 2022, with its numbers only growing month-over-month.

Nowadays, Raspberry Robin is a popular initial access option for threat actors like Evil Corp, TA505, and more, contributing to major breaches of public and private sector organizations.

“Most top malwares listed today are using worms to spread in networks because it’s very helpful — it saves a lot of hard work of developing these capabilities yourself,” Smadja explains. “For example, initial access to a system, bypassing security, and command-and-control infrastructure — you just need to buy it, combine it, and it makes your job much easier.”

This is especially true, he adds, “because tools like Raspberry Robin keep improving, using new zero-days and one-days, improving their infrastructure, and their evasion techniques. So I think it will never disappear. It’s an amazing service for an attacker.”



Editorial Team

Editorial Team

Related Posts

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale
Protection

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale

March 26, 2026
What Happens Now That Meta and YouTube Were Found Legally Negligent
Protection

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
If I Had a Home Gym, This Is the Storage Rack I'd Buy During Amazon's Spring Sale
Protection

If I Had a Home Gym, This Is the Storage Rack I’d Buy During Amazon’s Spring Sale

March 26, 2026
This Budget Fitbit Is Only $70 During Amazon's Big Spring Sale
Protection

This Budget Fitbit Is Only $70 During Amazon’s Big Spring Sale

March 26, 2026
This Surprisingly Powerful Compressed Air Duster Is 27% Off Today
Protection

This Surprisingly Powerful Compressed Air Duster Is 27% Off Today

March 26, 2026
Google's Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale
Protection

Google’s Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale

March 25, 2026
Load More
Next Post
Inflation expected to fall below 3% for the first time since March 2021

Inflation expected to fall below 3% for the first time since March 2021

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0

Latest News

Metanova Labs: Bittensor revolutionizes drug discovery with decentralized virtual screening, combinatorial reactions expand possibilities to 65 billion, and dual incentives drive innovation

Metanova Labs: Bittensor revolutionizes drug discovery with decentralized virtual screening, combinatorial reactions expand possibilities to 65 billion, and dual incentives drive innovation

March 26, 2026
0

Key takeaways Bittensor is a decentralized network that uses crypto incentives to reward contributions to AI models and compute. The...

Crypto

PM Keir Starmer Declares Total Ban On Crypto Donations To UK Political Parties

March 26, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The UK government moved on Wednesday to...

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale

March 26, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

RBA Projects $16.7B Annual Gain from RWA Tokenization

RBA Projects $16.7B Annual Gain from RWA Tokenization

March 26, 2026
0

The Reserve Bank of Australia is putting its support behind the real-world asset tokenization sector, citing recent analysis that it...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.