SuppoBox
Aliases: Bayrob, Nivdort, pizd
- First seen
- 2007-01-01 00:00:00
- Malware type
- botnet, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 02:11:37
- Profile updated
- 2026-07-07 15:21:51
Targeted industries: financial-services
Targeted regions: country_code:us country_code:ro
Context
SuppoBox, also known as Bayrob or Nivdort, is a malware family associated with cybercrime operations, often targeting financial information through trojan and botnet capabilities. It has been involved in large-scale fraudulent activities, particularly focusing on victims in the United States and Romania.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Suppobox_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Suppobox (report)
- media.blackhat.com — Us 13 Geffner End To End Analysis Of A Domain Generating Algorithm Malware Family Wp (report)
- Broadcom/Symantec — Bayrob Three Suspects Extradited Face Charges Us (report)
- Broadcom/Symantec — Trojanbayrob Strikes Again 1 (report)
- blog.avast.com — Your Facebook Connection Is Now Secured (report)
- justice.gov — Two Romanian Cybercriminals Convicted All 21 Counts Relating Infecting Over 400000 Victim (report)
- paper.bobylive.com — Us 13 Geffner End To End Analysis Of A Domain Generating Algorithm Malware Family Wp (report)