Bayrob is a Romanian cybercriminal group active since at least 2007 that conducted long-running malware-enabled fraud, credential theft, and money-laundering operations. The group is associated with large-scale spam distribution, botnet operations, phishing, auction fraud, and the use of infected systems for cryptocurrency mining. Known aliases include Bayrob and bayrob_group; publicly identified members tied to the operation include Bogdan Nicolescu, Radu Miclaus, and Danet Tiberiu. Bayrob initially became known for vehicle and high-value goods auction fraud that impersonated trusted online marketplaces and escrow services. The group used spoofed emails and malicious attachments to infect victims, then redirected them to convincing lookalike payment and escrow pages to steal credentials and induce fraudulent wire transfers. It also created fictitious companies, fraudulent business websites, fake seller reputations, and sham delivery or trucking services to support social engineering and delay victim suspicion. Proceeds were laundered through money transfer agents, fictitious companies, and networks of money mules. Operationally, Bayrob developed and deployed proprietary malware that spread through large malicious email campaigns impersonating well-known brands and government entities. The malware harvested email addresses, usernames, passwords, and financial data from infected systems; disabled security protections; blocked access to law-enforcement resources; and used compromised hosts to propagate further spam. The group also forced infected systems to create large numbers of email accounts for spam operations, redirected users from legitimate services to phishing pages, and used stolen payment data to fund criminal infrastructure. Over time, Bayrob expanded from fraud-focused activity into a large botnet operation that also leveraged victim machines for cryptocurrency mining. The group primarily targeted victims in the United States and operated as a financially motivated criminal enterprise rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Romania-based cybercriminal group convicted for operating a large-scale malware and fraud scheme involving malicious email distribution, credential and payment-card theft, cryptocurrency mining, phishing/redirection to fake websites, auction fraud, and money laundering.
A Romanian cybercriminal group conducting long-running online fraud operations, including fake vehicle auction scams, money mule recruitment, credit card theft, large-scale malicious email campaigns, and later botnet-driven cryptocurrency mining.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.