NOROBOT is a Windows downloader in the ROBOT malware suite associated with the Russian state-linked COLDRIVER threat actor, also tracked as Star Blizzard, Callisto, and UNC4057. It has been used in espionage-oriented intrusions against high-value targets, including government, policy, NGO, academic, media, civil-society, and Ukraine-related organizations. NOROBOT has commonly been delivered through ClickFix-style fake CAPTCHA lures that trick victims into executing a command that launches a malicious DLL through rundll32. The downloader has undergone frequent revisions intended to hinder detection and analysis, including changes to its staging logic, cryptographic-key handling, and intermediate components. Observed variants establish persistence through Windows logon scripts, scheduled tasks, and registry modifications, then retrieve and launch follow-on implants. Earlier chains installed a Python environment and the YESROBOT Python backdoor; later observed chains delivered the PowerShell-based MAYBEROBOT backdoor. NOROBOT has also been publicly tracked as BAITSWITCH. In later RedFlick activity attributed to Star Blizzard, a Control Panel applet-form downloader identified as NOROBOT or BAITSWITCH was used to install the CosmicPulse Python backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le downloader CosmicPulse (aussi connu sous NOROBOT ou BAITSWITCH) est compilé en DLL de panneau de contrôle (CPL) et exécuté via control.exe.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"...fetches a single file, which we observed to be a single command that sets up a logon script for persistence. The logon script was a Powershell command which downloaded and executed the next stage..."
"...fetches a single file, which we observed to be a single command that sets up a logon script for persistence. The logon script was a Powershell command which downloaded and executed the next stage..."
"...complex delivery chain that splits cryptographic keys across multiple components. Decrypting the final payload depended on combining the pieces correctly..."
A shortcut (LNK) file disguised as a PDF initiates the attack; scheduled tasks were named to look like normal network components.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader designation for the CosmicPulse downloader component, delivered and executed as a Control Panel DLL in the RedFlick infection chain.
Downloader used in the RedFlick infection chain to deliver the CosmicPulse backdoor.
A downloader masquerading as a Windows Control Panel item that retrieves and installs the CosmicPulse Python backdoor.
A Control Panel applet DLL downloader that retrieves, persists, and executes CosmicPulse. It downloads ZIP archives containing Python components and the encrypted CosmicPulse payload, and writes an encrypted AES key to the .mollis registry key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.