NOROBOT
Aliases: BAITSWITCH
- Malware type
- botnet, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 15:11:30
Targeted industries: financial-services government-and-public-sector
Context
NOROBOT, also known as BAITSWITCH, is a sophisticated botnet typically used to conduct various malicious operations such as data exfiltration and command-and-control activities. It primarily targets financial services and government sectors, often leveraging its loader capabilities to deploy additional payloads.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Norobot_Auto (yara-rule)
Reports & references
- cloud.google.com — New Malware Russia Coldriver (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Norobot (report)
- zscaler.com — Coldriver Updates Arsenal Baitswitch And Simplefix (report)