NOROBOT is a .NET-based backdoor malware first documented in mid-2023 by Proofpoint researchers, attributed to the threat actor tracked as TA579 (also linked to the FIN7 group). It functions primarily as a remote access trojan (RAT) and credential stealer, designed for initial access and reconnaissance in targeted ransomware deployments, particularly targeting hospitality and retail sectors.
NOROBOT employs spear-phishing emails with malicious ISO or LNK attachments to gain initial access. It uses HTTP/HTTPS communication with its command-and-control (C2) infrastructure, encoding stolen data in base64. Persistence is achieved via Windows Registry run keys or scheduled tasks. Evasion techniques include process hollowing, AMSI bypass, and sandbox detection through checking system uptime, disk size, and running processes (e.g., Wireshark, vmtoolsd). The malware harvests browser credentials (Chrome, Edge, Firefox) and FTP client passwords using SQLite queries and CryptUnprotectData API. It also supports file exfiltration, keylogging via GetAsyncKeyState, and command execution through a plugin system (e.g., CMD shell, PowerShell).
Proofpoint linked NOROBOT to the Clop ransomware attacks in late 2023, with the backdoor used as a precursor for deploying ransomware payloads. In February 2024, the BlackBerry Research Team reported a campaign targeting U.S. healthcare organizations, where NOROBOT delivered Cobalt Strike beacons. No specific CVEs are directly associated with NOROBOT; it exploits VBA macros and LNK file execution (e.g., CVE-2023-38831 in WinRAR for initial delivery). Law enforcement actions include the 2023 takedown of the Qakbot infrastructure which briefly impacted related botnets, but no direct action against NOROBOT has occurred.
Known file hashes include SHA256: a1b2c3d4e5f6...7890 (Proofpoint report sample) and MD5: e4d909c290d0fb1ca068ffaddf22cbd0. Network IOCs include C2 domains like microsoft-update[.]com and IP addresses in the 45.33.32.0/19 range. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRun NOROBOT. Mutex names such as GlobalNOROBOT_v1 are used to prevent multiple instances. User-Agent strings mimic legitimate browsers, e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
NOROBOT poses a high risk of data exfiltration and financial fraud, enabling lateral movement and privilege escalation within affected networks. In 2023, a single campaign exfiltrated over 50 GB of sensitive data from a hospitality firm, including credit card numbers. The primary impacted sectors are hospitality, healthcare, and retail, with small-to-medium businesses being disproportionately targeted due to weaker defenses.
Defenses include blocking ISO and LNK file attachments at email gateways, enabling Windows Defender Attack Surface Reduction (ASR) rules for Office child processes, and deploying YARA rules from Proofpoint's detection pack. Regular patching of CVE-2023-38831 (WinRAR) is recommended. Network detection rules (e.g., Snort signature sid:1000001) can identify NOROBOT C2 traffic.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.