Potential Raspberry Robin Registry Set Internet Settings ZoneMap

Rule Info

Name
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
Author
Swachchhanda Shrawan Poudel
Description
Detects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
Date
2024-07-31 00:00:00
Modified
None
Id
16a4c7b3-4681-49d0-8d58-3e9b796dcb43
Tags
detection.emerging-threats attack.t1112 attack.defense-evasion DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Swachchhanda Shrawan Poudel
Merge PR #4763 from @swachchhanda000 - New rules related to Raspberry Robin TTPs
2024-08-01