NOROBOT

Aliases: BAITSWITCH

Malware type
botnet, loader
Family
Malware family
Profile updated
2026-07-07 15:11:30

Targeted industries: financial-services government-and-public-sector

Context

NOROBOT, also known as BAITSWITCH, is a sophisticated botnet typically used to conduct various malicious operations such as data exfiltration and command-and-control activities. It primarily targets financial services and government sectors, often leveraging its loader capabilities to deploy additional payloads.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Norobot_Auto (yara-rule)

Reports & references

  • cloud.google.com — New Malware Russia Coldriver (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Norobot (report)
  • zscaler.com — Coldriver Updates Arsenal Baitswitch And Simplefix (report)

External references