Pikabot
MITRE ATT&CK: S1145 View on attack.mitre.org
Aliases: Pikabot
- First seen
- 2023-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 463 (104 malicious)
- Last IoC activity
- 2026-08-29 22:34:47
- Profile updated
- 2026-07-07 13:10:51
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
Pikabot is a backdoor used for initial access and follow-on tool deployment active since early 2023. Pikabot is notable for extensive use of multiple encoding, encryption, and defense evasion mechanisms to evade defenses and avoid analysis. Pikabot has some overlaps with QakBot, but insufficient evidence exists to definitively link these two malware families. Pikabot is frequently used to deploy follow on tools such as Cobalt Strike or ransomware variants.
Recent IoC activity
105 malicious indicators in Maltiverse are attributed to Pikabot (S1145). The 20 most recently updated:
Detection coverage
- 8 YARA rules
- 179 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Thread Execution Hijacking (attack-pattern)
- Debugger Evasion (attack-pattern)
- Non-Standard Port (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Local Account (attack-pattern)
- Native API (attack-pattern)
- System Information Discovery (attack-pattern)
- Fileless Storage (attack-pattern)
- Steganography (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Standard Encoding (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Embedded Payloads (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Environmental Keying (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Checks (attack-pattern)
Used by threat actors
- TA577 (threat-actor)
- Pikabot Distribution Campaigns 2023 (campaign)
- Pikabot Distribution February 2024 (campaign)
- Water Curupira Pikabot Distribution (campaign)
Detection rules
- MALPEDIA_Win_Pikabot_Auto (yara-rule)
- RUSSIANPANDA_Pikabot_1 (yara-rule)
- EMBEERESEARCH_Win_Pikabot_Loader_Bytecodes_Oct_2023 (yara-rule)
- CAPE_Pikahook (yara-rule)
- CAPE_Pikexport (yara-rule)
- CAPE_Pikabotloader (yara-rule)
- CAPE_Pikabot (yara-rule)
- CAPE_Pik23 (yara-rule)
Reports & references
- Trend Micro — A Look Into Pikabot Spam Wave Campaign (report)
- intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- securityintelligence.com — Spam Trends Campaigns Senior Superlatives 2023 (report)
- darkreading.com — Operation Endgame Takedowns Arrests Matter (report)
- malware-traffic-analysis.net — Index (report)
- cofense.com — Are Darkgate And Pikabot The New Qakbot (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pikabot (report)
- blog.pulsedive.com — Pikabot (report)
- d01a.github.io — Pikabot (report)
- hivepro.com — Pikabot A Stealthy Backdoor With Ingenious Evasion Tactics Ta2023246 (report)
- blog.cyber5w.com — Pikabotloader (report)
- vmray.com — Why Your Edr Let Pikabot Jump Through (report)
- elastic.co — Pikabot I Choose You (report)
- youtube.com — Watch (report)
- github.com — Pikabot%20Loader.Md (report)
- blog.krakz.fr — Syswhispers2 (report)
- youtube.com — Watch (report)
- blog.cyber5w.com — Pikabotloader (report)
- minerva-labs.com — Beepin Out Of The Sandbox Analyzing A New Extremely Evasive Malware (report)
- malwarebytes.com — Pikabot Distributed Via Malicious Ads (report)
- news.sophos.com — Deep Dive Into The Pikabot Cyber Threat (report)
- blog.securityonion.net — Quick Malware Analysis Pikabot (report)
- kienmanowar.wordpress.com — Quicknote Technical Analysis Of Recent Pikabot Core Module (report)