Microsoft experts linked the Raspberry Robin malware to Evil Corp operation
The malware uses cmd.exe to read and execute a file stored on the infected external drive, it leverages msiexec.exe for external network communication to a rogue domain used as C2 to download and install a DLL library file.